Description
A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when another user views the file.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-7569 | A stored cross-site scripting vulnerability exists in TCExam <= 14.8.1. Valid files uploaded via tce_select_mediafile.php with a filename beggining with a period will be rendered as text/html. An attacker with access to tce_select_mediafile.php could upload a malicious javascript payload which would be triggered when another user views the file. |
References
| Link | Providers |
|---|---|
| https://www.tenable.com/security/research/tra-2021-32 |
|
History
No history.
Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-03T17:30:07.345Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20112
No data.
Status : Modified
Published: 2021-07-30T14:15:14.317
Modified: 2024-11-21T05:45:56.760
Link: CVE-2021-20112
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD