ZeroHour

Vulnerabilities

18 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-6554
When access to the "admin" folder is not protected by some external authorization mechanisms e.g.

When access to the "admin" folder is not protected by some external authorization mechanisms e.g. Apache Basic Auth, it is possible for any user to download protected information like exam answers.

NVD description · AI analysis pending
6.5<1%
  • tecnick tcexam
CVE-2021-20115
+1 in the same advisory: …20116
A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3.

A reflected cross-site scripting vulnerability exists in TCExam <= 14.8.3. The paths provided in the f, d, and dir parameters in tce_filemanager.php were not properly validated and could cause reflected XSS via the unsanitized output of the path supplied. An attacker could craft a malicious link which, if triggered by an administrator, could result in the attacker hijacking the victim's session or performing actions on their behalf.

NVD description · AI analysis pending
6.1<1% PoC
  • tecnick tcexam
CVE-2021-20114
+3 in the same advisory: …20112 …20111 …20113
When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included

When installed following the default/recommended settings, TCExam <= 14.8.1 allowed unauthenticated users to access the /cache/backup/ directory, which included sensitive database backup files.

NVD description · AI analysis pending
7.5
group max
6% PoC
  • tecnick tcexam
CVE-2020-5745
Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a craft

Cross-site request forgery in TCExam 14.2.2 allows a remote attacker to perform sensitive application actions by tricking legitimate users into clicking a crafted link.

NVD description · AI analysis pending
7.4
group max
<1% PoC
  • tecnick tcexam
CVE-2018-17057
An issue was discovered in TCPDF before 6.2.22.

An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

NVD description · AI analysis pending
9.826% PoC
  • tecnick tcpdf
  • tecnick limesurvey
CVE-2018-13422
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

TCExam before 14.1.2 has XSS via an ff_ or xl_ field.

NVD description · AI analysis pending
6.1<1%
  • tecnick tcexam