CVE-2023-45121

Publication date

2023-12-21 16:23:47

Family

Fluid Attacks

State

PUBLISHED

Description

Online Examination System v1.0 is vulnerable to multiple Authenticated SQL Injection vulnerabilities. The desc parameter of the /update.php?q=addquiz resource does not validate the characters received and they are sent unfiltered to the database.