Reflected Cross-Site Scripting Vulnerability in TCExam by TCExam
CVE-2021-20115
6.1MEDIUM
What is CVE-2021-20115?
A reflected cross-site scripting vulnerability in TCExam prior to version 14.8.3 allows an attacker to exploit insufficient input validation within the tce_filemanager.php file. Attackers can manipulate the f, d, and dir parameters to craft a malicious link. If an administrator is tricked into clicking this link, it can lead to session hijacking or unauthorized actions performed on their behalf, primarily impacting the security and integrity of user data.
Affected Version(s)
TCExam <= 14.8.3