Description
Insufficient output sanitization in TCExam 14.2.2 allows a remote, authenticated attacker to conduct persistent cross-site scripting (XSS) attacks by creating a crafted operator.
Remediation
References
Related Vulnerabilities
Magento Exposure of Sensitive Information to an Unauthorized Actor Vulnerability (CVE-2020-9591)
WordPress Plugin Shariff for WordPress Cross-Site Scripting (1.0.7)
MySQL Improper Access Control Vulnerability (CVE-2016-8288)
Joomla Other Vulnerability (CVE-2007-4185)
WordPress Plugin All-In-One Security (AIOS)-Security and Firewall SQL Injection (4.0.8)