CVE-2012-4237: Tecnick Tcexam

Medium severity, CVSS 6.8. EPSS: 2.4% chance of exploitation in the next 30 days.

Multiple SQL injection vulnerabilities in TCExam before 11.3.008 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the subject_module_id parameter to (1) tce_edit_answer.php or (2) tce_edit_question.php.

Affected products

  • Tecnick Tcexam: up to and including 11.3.007; version 10.1.000 only; version 10.1.001 only; version 10.1.002 only; version 10.1.003 only; version 10.1.004 only; …

Published 2012-08-20. Last modified 2026-06-16.