---
id: CVE-2022-50896
title: >-
  Testa 3.5.1 Online Test Management System - Reflected Cross-Site Scripting
  (XSS)
summary: >-
  Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the
  login.php redirect parameter that allows attackers to inject malicious
  scripts. Attackers can craft a specially encoded payload in the redirect
  parameter to execu…
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cvssSource: cna
cwe:
  - CWE-79
vendor: Testa
product: Testa
affected:
  - Testa 3.5.1
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-01-14T15:05:07.839710Z'
exploitAvailable: true
published: '2026-01-13'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T15:19:42.023Z'
source: CVEORG
sourceUrl: 'https://www.cve.org/CVERecord?id=CVE-2022-50896'
references:
  - url: 'https://www.exploit-db.com/exploits/51023'
    label: ExploitDB-51023
  - url: 'https://web.archive.org/web/20220406031253/https://testa.cc/'
    label: Archived Product Homepage
  - url: >-
      https://www.vulncheck.com/advisories/testa-online-test-management-system-reflected-cross-site-scripting-xss
    label: >-
      VulnCheck Advisory: Testa 3.5.1 Online Test Management System - Reflected
      Cross-Site Scripting (XSS)
tags:
  - cve.org
  - exploit-available
epss: 0.00389
epssPercentile: 0.30605
ingestedAt: '2026-10-01T15:48:17.874Z'
---

## Overview

Testa 3.5.1 contains a reflected cross-site scripting vulnerability in the login.php redirect parameter that allows attackers to inject malicious scripts. Attackers can craft a specially encoded payload in the redirect parameter to execute arbitrary JavaScript in victim's browser context.

## Affected

- `Testa 3.5.1`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
