CVE-2026-4169

Source
https://cve.org/CVERecord?id=CVE-2026-4169
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4169.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-4169
Published
2026-03-16T14:19:56.593Z
Modified
2026-04-10T05:43:25.544479Z
Severity
  • 2.4 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N CVSS Calculator
Summary
[none]
Details

A security flaw has been discovered in Tecnick TCExam up to 16.6.0. Affected is the function Fxmlexportusers of the file admin/code/tcexml_users.php of the component XML Export. Performing a manipulation results in cross site scripting. Remote exploitation of the attack is possible. There are still doubts about whether this vulnerability truly exists. Upgrading to version 16.6.1 is able to address this issue. The patch is named 899b5b2fa09edfe16043f07265e44fe2022b7f12. It is suggested to upgrade the affected component. When the vendor was informed about another security issue, he identified and fixed this flaw during analysis. He doubts the impact of this: "However, this is difficult to justify as security issue. It requires to be administrator to both create and consume the exploit. Administrators can do pretty much anything in the platform, so I don't see the point of this from a security perspective." This is reflected by the CVSS vector.

References

Affected packages

Git / github.com/tecnickcom/tcexam

Affected ranges

Type
GIT
Repo
https://github.com/tecnickcom/tcexam
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Type
GIT
Repo
https://github.com/tecnickcom/tcexam
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

12.*
12.0.013
12.0.014
12.1.000
12.1.001
12.1.002
12.1.003
12.1.004
12.1.005
12.1.006
12.1.007
12.1.008
12.1.009
12.1.010
12.1.011
12.1.012
12.1.013
12.1.014
12.1.015
12.1.016
12.1.017
12.1.018
12.1.019
12.1.020
12.1.021
12.1.022
12.1.023
12.1.024
12.1.025
12.1.026
12.1.027
12.1.28
12.1.29
12.1.30
12.2.0
12.2.1
12.2.2
12.2.3
12.2.4
12.2.5
13.*
13.0.1
13.0.2
13.1.1
13.2.0
13.2.1
13.3.0
14.*
14.0.0
14.0.1
14.0.2
14.0.3
14.1.0
14.1.2
14.1.3
14.1.4
14.2.1
14.2.2
14.2.3
14.3.0
14.3.1
14.3.2
14.4.0
14.4.1
14.5.0
14.5.1
14.5.2
14.6.0
14.7.0
14.8.0
14.8.1
14.8.2
14.8.3
14.8.4
14.8.5
15.*
15.0.0
15.0.1
16.*
16.3.1
16.3.2
16.3.4
16.3.5
16.3.6
16.3.7
16.3.9
16.4.0
16.5.0
16.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-4169.json"