← back
CVE-2022-50896

Testa 3.5.1 Online Test Management System - Reflected Cross-Site Scripting (XSS)

CVSS 5.1 MEDIUMEPSS 0.3%CWE-79
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N
Affected products
Testa · Testa

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →