CVE-2025-51567
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 3.9 / Impact: 5.2
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)
Description
A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.
Affected (1)
Products: Jayesh: Online Exam System
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.0 |
References (1)
Source: cve@mitre.org
ExploitThird Party Advisory
Timeline
No history available yet.