CVE-2023-45120
21.12.2023, 17:15
Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities.The 'qid' parameter of the /update.php?q=quiz&step=2 resourcedoes not validate the characters received and theyare sent unfiltered to the database.
| Vendor | Product | Version |
|---|---|---|
| projectworlds | online_examination_system | 1.0 |
𝑥
= Vulnerable software versions