PT-2026-7005 · Code Projects · Online Examination System

Imcoming

·

Publicado

2026-02-08

·

Atualizado

2026-02-09

·

CVE-2026-2173

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions code-projects Online Examination System version 1.0
Description A flaw exists in the Online Examination System that allows for SQL injection through the manipulation of the username and password arguments in the login.php file. This issue can be exploited remotely.
Recommendations Apply input validation and sanitization to the username and password parameters in the login.php file.

Correção

SQL injection

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-2173

Produtos afetados

Online Examination System