Vulnerabilities
18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-6554 | When access to the "admin" folder is not protected by some external authorization mechanisms e.g. When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers. NVD description · AI analysis pending | 6.5 | <1% |
| — | ||
| CVE-2021-20115 +1 in the same advisory: …20116 | A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf. NVD description · AI analysis pending | 6.1 | <1% | PoC |
| — | |
| CVE-2021-20114 | When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files. NVD description · AI analysis pending | 7.5 group max | 6% | PoC |
| — | |
| CVE-2020-5745 | Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a craft Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link. NVD description · AI analysis pending | 7.4 group max | <1% | PoC |
| — | |
| CVE-2018-17057 | An issue was discovered in TCPDF before 6.2.22. An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. NVD description · AI analysis pending | 9.8 | 26% | PoC |
| — | |
| CVE-2018-13422 | TCExam before 14.1.2 has XSS via an ff_ or xl_ field. TCExam before 14.1.2 has XSS via an ff_ or xl_ field. NVD description · AI analysis pending | 6.1 | <1% |
| — |