TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-5747 - Vulnerability Database

TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability - CVE-2020-5747

Medium
Reference: CVE-2020-5747
Title: TCExam Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) Vulnerability
Overview:

Insufficient output sanitization in TCExam 14.2.2 allows a remote authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.