First published: Wed Nov 01 2023(Updated: )
Online Examination System v1.0 is vulnerable to multiple Open Redirect vulnerabilities. The 'q' parameter of the feed.php resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL.
Credit: help@fluidattacks.com
Affected Software | Affected Version | How to fix |
---|---|---|
Projectworlds Online Examination System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45202 is a vulnerability in Online Examination System v1.0 that allows attackers to redirect users to arbitrary websites.
The 'q' parameter of the feed.php resource in Online Examination System v1.0 can be manipulated by attackers to redirect users to any website of their choice.
The severity of CVE-2023-45202 is medium with a CVSS score of 6.1.
To fix CVE-2023-45202, it is recommended to update Online Examination System to a version that addresses the Open Redirect vulnerabilities.
More information about CVE-2023-45202 can be found at the following references: [https://fluidattacks.com/advisories/uchida](https://fluidattacks.com/advisories/uchida) and [https://projectworlds.in/](https://projectworlds.in/).