PT-2021-4018 · Tcexam · Tcexam
Derrie Sutton
·
Published
2021-07-21
·
Updated
2021-08-12
·
CVE-2021-20116
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
TCExam versions prior to 14.8.5
Description
A reflected cross-site scripting issue exists due to improper validation of paths provided in the
f, d, and dir parameters in tce select mediafile.php. This could cause reflected XSS via unsanitized output of the supplied path. An attacker could craft a malicious link that, if triggered by an administrator, could result in session hijacking or actions performed on the victim's behalf.Recommendations
For versions prior to 14.8.5, update to version 14.8.5 or later to resolve the issue.
As a temporary workaround, consider restricting access to the
tce select mediafile.php file until a patch is available.
Avoid using the parameters f, d, and dir in the affected API endpoint until the issue is resolved.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tcexam