Tecnick

Tcexam

27 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.21%
  • Veröffentlicht 30.07.2021 14:15:14
  • Zuletzt bearbeitet 21.11.2024 05:45:56

A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a ...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted group.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:32

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.

Exploit
  • EPSS 1.28%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:32

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

Exploit
  • EPSS 1.14%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.

Exploit
  • EPSS 0.16%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 07.05.2020 17:15:12
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

Exploit
  • EPSS 0.3%
  • Veröffentlicht 07.05.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Relative Path Traversal in TCExam 14.2.2 allows a remote, authenticated attacker to read the contents of arbitrary files on disk.

Exploit
  • EPSS 0.14%
  • Veröffentlicht 07.05.2020 17:15:11
  • Zuletzt bearbeitet 21.11.2024 05:34:31

Improper Control of Resource Identifiers in TCExam 14.2.2 allows a remote, authenticated attacker to access test metadata for which they don't have permission.