TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-5746 - Vulnerability Database
TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-5746
Medium
Reference:
CVE-2020-5746
Title:
TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:
Insufficient output sanitization in TCExam 14.2.2 allows a remote authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.