SQL Injection Vulnerability in Campcodes Online Examination System
CVE-2024-2941
What is CVE-2024-2941?
A serious SQL injection vulnerability has been identified in the Campcodes Online Examination System version 1.0, specifically within the file /adminpanel/admin/query/loginExe.php. This critical flaw arises from improper input validation of the 'pass' argument, allowing attackers to manipulate query execution. The vulnerability can be exploited remotely, potentially compromising the integrity of the database and exposing sensitive user data. Given the public disclosure of this exploit, organizations using this examination system must act urgently to mitigate associated risks.
Affected Version(s)
Online Examination System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved