SourceCodester Online Exam System data sql injection
CVE-2023-2771
8.8HIGH
What is CVE-2023-2771?
A significant vulnerability has been uncovered within the SourceCodester Online Exam System version 1.0, centered on the inadequate handling of parameters in the /jurusanmatkul/data file. Specifically, an attacker can manipulate the arguments, particularly columns[1][data], to execute SQL injection attacks. This vulnerability allows remote exploitation, potentially leading to unauthorized access to sensitive data. Public disclosure of the exploit has raised concerns about its active use in the wild, making immediate remedial actions critical for affected users.
Affected Version(s)
Online Exam System 1.0