Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.
Remediation
References
Related Vulnerabilities
WordPress Plugin ARPrice-Responsive Pricing Table Cross-Site Scripting (2.2)
WordPress Plugin Filedownload 'download.php' Local File Disclosure (0.1)
WordPress 4.6.x Prototype Pollution (4.6 - 4.6.22)
MySQL CVE-2018-3064 Vulnerability (CVE-2018-3064)
LiteSpeed Web Server Out-of-bounds Read Vulnerability (CVE-2004-0112)