Description
Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.
Problem types
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Product status
Credits
Ashkan Moghaddas
References
www.exploit-db.com/exploits/51023 (ExploitDB-51023)
web.archive.org/web/20220406031253/https://testa.cc/ (Archived Product Homepage)
www.vulncheck.com/...stem-reflected-cross-site-scripting-xss (VulnCheck Advisory: Testa 3.5.1 Online Test Management System - Reflected Cross-Site Scripting (XSS))