Vulnerabilities > Taotesting

DATE CVE VULNERABILITY TITLE RISK
2021-10-22 CVE-2020-23050 Injection vulnerability in Taotesting TAO Assessment Platform 3.3.0
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a HTML injection vulnerability in the userFirstName parameter of the user account input field.
network
low complexity
taotesting CWE-74
8.0
2021-10-22 CVE-2020-36499 Cross-site Scripting vulnerability in Taotesting Assessment Platform 3.3.0
TAO Open Source Assessment Platform v3.3.0 RC02 was discovered to contain a cross-site scripting (XSS) vulnerability in the content parameter of the Rubric Block (Add) module.
network
taotesting CWE-79
3.5