CVE-2012-4601: Tecnick Tcexam
Medium severity, CVSS 6.0. EPSS: 1.6% chance of exploitation in the next 30 days.
Multiple SQL injection vulnerabilities in Nicola Asuni TCExam before 11.3.009 allow remote authenticated users with level 5 or greater permissions to execute arbitrary SQL commands via the (1) user_groups[] parameter to admin/code/tce_edit_test.php or (2) subject_id parameter to admin/code/tce_show_all_questions.php.
Affected products
- Tecnick Tcexam: up to and including 11.3.008; version 10.1.000 only; version 10.1.001 only; version 10.1.002 only; version 10.1.003 only; version 10.1.004 only; …
Published 2012-11-23. Last modified 2026-06-16.