CVE-2023-45120
EUVD-2023-4944121.12.2023, 17:15
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The 'qid' parameter of the /update.php?q=quiz&step=2 resource does not validate the characters received and they are sent unfiltered to the database.
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| projectworlds | online_examination_system | 1.0 |
𝑥
= Vulnerable software versions