SourceCodester Online Exam System data sql injection
CVE-2023-2770
8.8HIGH
What is CVE-2023-2770?
An SQL injection vulnerability exists in SourceCodester's Online Exam System 1.0, specifically within the /kelasdosen/data file. Malicious actors can exploit this flaw by manipulating the argument columns[1][data], allowing for unauthorized access to the underlying database. This manipulation can be performed remotely, making it a significant security concern. The potential for data leakage or corruption is high, as attackers can execute arbitrary SQL queries. Awareness of this vulnerability is crucial as its details have been made public, increasing the risk of exploitation.
Affected Version(s)
Online Exam System 1.0