Description
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-7568 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_filemanager.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_filemanager.php could upload a malicious javascript payload which would be triggered when another user views the file. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2021-32 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-03T17:30:07.606Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20111
No data.
Status : Modified
Published: 2021-07-30T14:15:14.283
Modified: 2024-11-21T05:45:56.637
Link: CVE-2021-20111
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD