TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-13422 - Vulnerability Database
TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2018-13422
Medium
Reference:
CVE-2018-13422
Title:
TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.