SQL Injection Vulnerability in Exam Form Submission by PHP
CVE-2023-42359
9.8CRITICAL
Key Information:
- Vendor
- CVE Published:
- 18 September 2023
What is CVE-2023-42359?
The Exam Form Submission in PHP version 1.0 is vulnerable to SQL injection due to improper validation of the val-username parameter in the /index.php file. A remote attacker can exploit this vulnerability to execute arbitrary SQL commands, potentially escalating their privileges within the application. This could lead to unauthorized access and manipulation of sensitive data.