PT-2025-51170 · Campcodes · Campcodes Advanced Online Examination System
Duanzhoutao
·
Published
2025-12-14
·
Updated
2025-12-14
·
Duanzhoutao
·
Published
2025-12-14
·
Updated
2025-12-14
·
9.8
Critical
| Base vector | Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
/query/loginExe.php and involves manipulation of the Username argument. The exploit is publicly available.Username argument in the /query/loginExe.php file.Exploit
Fix
SQL injection
Special Elements Injection