A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.
References
| Link | Resource |
|---|---|
| https://github.com/0xBhushan/Writeups/blob/main/CVE/Kashipara/Online%20Exam%20System/SQL%20Injection-Profile%20Update.pdf | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-01-12 20:15
Updated : 2026-01-16 17:31
NVD link : CVE-2025-51567
Mitre link : CVE-2025-51567
CVE.ORG link : CVE-2025-51567
JSON object : View
Products Affected
jayesh
- online_exam_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
