A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
Metrics
Affected Vendors & Products
References
History
Sun, 22 Dec 2024 06:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability classified as critical has been found in code-projects Online Exam Mastering System 1.0. Affected is an unknown function of the file /account.php?q=quiz&step=2. The manipulation of the argument eid leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
Title | code-projects Online Exam Mastering System account.php sql injection | |
Weaknesses | CWE-74 CWE-89 |
|
References |
| |
Metrics |
cvssV2_0
|
MITRE
Status: PUBLISHED
Assigner: VulDB
Published: 2024-12-22T06:31:06.289Z
Updated: 2024-12-22T06:31:06.289Z
Reserved: 2024-12-21T09:00:35.378Z
Link: CVE-2024-12891
Vulnrichment
No data.
NVD
Status : Received
Published: 2024-12-22T07:15:04.910
Modified: 2024-12-22T07:15:04.910
Link: CVE-2024-12891
Redhat
No data.