CVE-2024-40479 Information

Description

A SQL injection vulnerability in /admin/quizquestion.php\ in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the id\ parameter.

Reference

https://www.kashipara.com/project/php/3/online-exam-php-project-source-code-download https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Online%20Exam%20System%20v1.0/SQL%20Injection.pdf

Share on: