CVE-2021-20111
- EPSS 0.21%
- Veröffentlicht 30.07.2021 14:15:14
- Zuletzt bearbeitet 21.11.2024 05:45:56
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a ...
CVE-2020-5749
- EPSS 0.16%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:31
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted group.
CVE-2020-5751
- EPSS 0.16%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:32
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.
CVE-2020-5750
- EPSS 1.28%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:32
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
CVE-2020-5748
- EPSS 1.14%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:31
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
CVE-2020-5747
- EPSS 0.16%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:31
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
CVE-2020-5746
- EPSS 0.16%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:31
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
CVE-2020-5745
- EPSS 0.15%
- Veröffentlicht 07.05.2020 17:15:12
- Zuletzt bearbeitet 21.11.2024 05:34:31
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.
CVE-2020-5744
- EPSS 0.3%
- Veröffentlicht 07.05.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:31
Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.
CVE-2020-5743
- EPSS 0.14%
- Veröffentlicht 07.05.2020 17:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:31
Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.