PT-2026-25542 · Tecnick+1 · Tcexam

·

CVE-2026-4169

·

Published

2026-03-15

·

Updated

2026-03-16

CVSS v4.0

4.8

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:X
Name of the Vulnerable Software and Affected Versions Tecnick TCExam versions up to 16.6.0
Description A security issue exists in Tecnick TCExam related to the XML Export component. The F xml export users function within the admin/code/tce xml users.php file is susceptible to cross site scripting. Exploitation may be possible remotely. The vendor has expressed doubts about the severity of this issue, noting that it requires administrator privileges for both creation and exploitation, and that administrators already possess extensive capabilities within the platform.
Recommendations Tecnick TCExam versions up to 16.6.0 should be upgraded to version 16.6.1 to address this issue.

Exploit

Fix

XSS

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-4169

Affected Products

Tcexam