CVE-2012-4238

UnknownEPSS 0.97%

Last modified

CVE-2012-4238 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.. EPSS estimates a 0.97% chance of exploitation in the next 30 days.

Description

Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.

Metrics

EPSS Probability
0.97%

57.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TecnickTcexam<= 11.3.007
TecnickTcexam10.1.000
TecnickTcexam10.1.001
TecnickTcexam10.1.002
TecnickTcexam10.1.003
TecnickTcexam10.1.004
TecnickTcexam10.1.005
TecnickTcexam10.1.006
TecnickTcexam10.1.007
TecnickTcexam10.1.008
TecnickTcexam10.1.009
TecnickTcexam10.1.010
TecnickTcexam10.1.011
TecnickTcexam10.1.012
TecnickTcexam10.1.013
TecnickTcexam11.0.000
TecnickTcexam11.0.001
TecnickTcexam11.0.002
TecnickTcexam11.0.003
TecnickTcexam11.0.004
TecnickTcexam11.0.005
TecnickTcexam11.0.006
TecnickTcexam11.0.007
TecnickTcexam11.0.008
TecnickTcexam11.0.009
TecnickTcexam11.0.010
TecnickTcexam11.0.011
TecnickTcexam11.0.012
TecnickTcexam11.0.013
TecnickTcexam11.0.014
TecnickTcexam11.0.015
TecnickTcexam11.0.016
TecnickTcexam11.1.000
TecnickTcexam11.1.001
TecnickTcexam11.1.002
TecnickTcexam11.1.003
TecnickTcexam11.1.004
TecnickTcexam11.1.005
TecnickTcexam11.1.006
TecnickTcexam11.1.007
TecnickTcexam11.1.008
TecnickTcexam11.1.009
TecnickTcexam11.1.010
TecnickTcexam11.1.011
TecnickTcexam11.1.012
TecnickTcexam11.1.013
TecnickTcexam11.1.014
TecnickTcexam11.1.015
TecnickTcexam11.1.016
TecnickTcexam11.1.017

Showing 50 of 101 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2012-4238?
Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.
How severe is CVE-2012-4238?
Severity scoring for CVE-2012-4238 is pending analysis. The EPSS model estimates a 0.97% probability of exploitation in the next 30 days.
How do I fix CVE-2012-4238?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2012-4238?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST