CVE-2012-4238: Tecnick Tcexam

Low severity, CVSS 2.1. EPSS: 1% chance of exploitation in the next 30 days.

Cross-site scripting (XSS) vulnerability in admin/code/tce_edit_answer.php in TCExam before 11.3.008 allows remote authenticated users with level 5 or greater permissions to inject arbitrary web script or HTML via the question_subject_id parameter.

Affected products

  • Tecnick Tcexam: up to and including 11.3.007; version 10.1.000 only; version 10.1.001 only; version 10.1.002 only; version 10.1.003 only; version 10.1.004 only; …

Published 2012-08-20. Last modified 2026-06-16.