PT-2017-14918 · Unknown · Online Exam Test Application Script

Ihsan Sencan

·

Published

2017-12-13

·

Updated

2017-12-26

·

CVE-2017-17622

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Online Exam Test Application Script version 1.6
Description The issue is related to SQL Injection, which occurs via the sort parameter in the "exams.php" API endpoint. This allows for potential manipulation of database queries.
Recommendations For version 1.6, consider restricting access to the exams.php endpoint or avoiding the use of the sort parameter until a fix is available. As a temporary workaround, validate and sanitize all user input to prevent malicious SQL queries.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-17622

Affected Products

Online Exam Test Application Script