CVE-2024-4915: Campcodes Online Examination System result.php sql injection
A vulnerability, which was classified as critical, was found in Campcodes Online Examination System 1.0. Affected is an unknown function of the file result.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. VDB-264450 is the identifier assigned to this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-4915?
CVE-2024-4915 is classified as critical due to its potential for remote exploitation via SQL injection.
How do I fix CVE-2024-4915?
To fix CVE-2024-4915, validate and sanitize all user input, particularly the 'id' parameter, to prevent SQL injection attacks.
Can CVE-2024-4915 be exploited remotely?
Yes, CVE-2024-4915 can be exploited remotely, allowing attackers to perform unauthorized actions on the affected system.
What component of Campcodes Online Examination System is affected by CVE-2024-4915?
CVE-2024-4915 affects an unknown function in the file result.php of Campcodes Online Examination System.
Which version of Campcodes Online Examination System is vulnerable to CVE-2024-4915?
Version 1.0 of Campcodes Online Examination System is vulnerable to CVE-2024-4915.