First published: Wed May 15 2024(Updated: )
A vulnerability classified as critical has been found in Campcodes Online Examination System 1.0. This affects an unknown part of the file addExamExe.php. The manipulation of the argument examTitle leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-264447.
Credit: cna@vuldb.com
Affected Software | Affected Version | How to fix |
---|---|---|
Campcodes Online Examination System | ||
Campcodes Online Examination System | =1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-4912 is classified as a critical vulnerability.
CVE-2024-4912 allows SQL injection through manipulation of the examTitle argument in addExamExe.php.
Yes, CVE-2024-4912 can be exploited remotely.
CVE-2024-4912 affects version 1.0 of the Campcodes Online Examination System.
To fix CVE-2024-4912, sanitize inputs related to the examTitle argument to prevent SQL injection.