PT-2021-4014 · Tcexam · Tcexam

Derrie Sutton

·

Published

2021-07-15

·

Updated

2021-08-02

·

CVE-2021-20111

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions TCExam versions prior to 14.8.2
Description A stored cross-site scripting issue exists, allowing an attacker to upload a malicious JavaScript payload via tce filemanager.php with a filename starting with a period. This payload would be triggered when another user views the file, potentially leading to cross-site scripting attacks. The vulnerability is related to the incorrect rendering of files starting with a period as text/html.
Recommendations For TCExam versions prior to 14.8.2, update to version 14.8.2 or later to resolve the issue. As a temporary workaround, consider restricting access to tce filemanager.php to minimize the risk of exploitation.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04540
CVE-2021-20111

Affected Products

Tcexam