Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted test.
Remediation
References
Related Vulnerabilities
WordPress Plugin Allow REL= and HTML in Author Bios Cross-Site Scripting (.1)
Django Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2018-6188)
WordPress 4.3.x Same Origin Method Execution (SOME) Vulnerability (4.3 - 4.3.3)
WordPress Plugin BackupBuddy Multiple Vulnerabilities (8.0.1.8)