Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, unauthenticated attacker to conduct persistent cross-site scripting (XSS) attacks via the self-registration feature.
Remediation
References
Related Vulnerabilities
WordPress Plugin Quick Cache (Speed Without Compromise) Unspecified Vulnerability (140725)
Serendipity Other Vulnerability (CVE-2005-1450)
PHP Time-of-check Time-of-use (TOCTOU) Race Condition Vulnerability (CVE-2004-0594)
Jboss EAP Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2014-3518)