Home

Description

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

PUBLISHED Reserved 2025-06-16 | Published 2026-01-12 | Updated 2026-01-12 | Assigner mitre

References

github.com/...e Exam System/SQL Injection-Profile Update.pdf

cve.org (CVE-2025-51567)

nvd.nist.gov (CVE-2025-51567)

Download JSON