First published: Thu Aug 15 2024(Updated: )
Projectworlds Online Examination System v1.0 is vulnerable to SQL Injection via the subject parameter in feed.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
SourceCodester Online Examination System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-42843 has been classified with a high severity due to its potential for SQL Injection vulnerabilities.
To fix CVE-2024-42843, validate and sanitize all user inputs, especially the subject parameter in feed.php.
CVE-2024-42843 affects Projectworlds Online Examination System version 1.0.
SQL Injection in CVE-2024-42843 refers to the attack vector that allows an attacker to manipulate SQL queries through the subject parameter, potentially compromising the database.
As of the latest information, there are no confirmed reports of exploitation specifically related to CVE-2024-42843.