Online Examination System v1.0 - Multiple Authenticated SQL Injections (SQLi)
CVE-2023-45118
8.8HIGH
What is CVE-2023-45118?
The Online Examination System v1.0 is subject to multiple authenticated SQL injection vulnerabilities due to insufficient input validation on the 'fdid' parameter in the /update.php resource. This lack of proper sanitization allows attackers to manipulate queries sent to the database, potentially leading to unauthorized access or data alteration.
Affected Version(s)
Online Examination System 1.0