Home

Description

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

PUBLISHED Reserved 2026-01-28 | Published 2026-01-30 | Updated 2026-01-30 | Assigner VulnCheck




HIGH: 8.8CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
HIGH: 8.2CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

Problem types

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Product status

2015
affected

Credits

Berk Dusunur finder

References

www.exploit-db.com/exploits/48529 (ExploitDB-48529) exploit

github.com/sunnygkp10/Online-Exam-System-.git (Software Repository) product

www.vulncheck.com/...es/online-exam-system-fid-sql-injection (VulnCheck Advisory: Online-Exam-System 2015 - 'fid' SQL Injection) third-party-advisory

cve.org (CVE-2020-37057)

nvd.nist.gov (CVE-2020-37057)

Download JSON