SQL Injection Vulnerability in Projectworlds Online Examination System
CVE-2024-42843
9.8CRITICAL
What is CVE-2024-42843?
The Projectworlds Online Examination System version 1.0 is susceptible to SQL Injection attacks through the manipulation of the 'subject' parameter in the feed.php file. This vulnerability allows attackers to execute arbitrary SQL queries, potentially exposing sensitive user data and compromising the overall security of the system. Preventative measures are crucial to mitigate the risks associated with this vulnerability.