Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi)
CVE-2023-45115
8.8HIGH
What is CVE-2023-45115?
The Online Examination System version 1.0 is susceptible to multiple Authenticated SQL Injection vulnerabilities due to inadequate validation of the 'ch' parameter in the /update.php?q=addqns endpoint. This oversight allows attackers to send unfiltered data to the database, potentially leading to unauthorized access and manipulation of sensitive information.
Affected Version(s)
Online Examination System 1.0