CVE-2023-1474
Published on: Not Yet Published
Last Modified on: 03/23/2023 03:01:00 PM UTC
Certain versions of Automatic Question Paper Generator System from Automatic Question Paper Generator System Project contain the following vulnerability:
A vulnerability classified as critical was found in SourceCodester Automatic Question Paper Generator System 1.0. This vulnerability affects unknown code of the file users/question_papers/manage_question_paper.php of the component GET Parameter Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-223336.
- CVE-2023-1474 has been assigned by
[email protected] to track the vulnerability - currently rated as CRITICAL severity.
- Affected Vendor/Software:
SourceCodester - Automatic Question Paper Generator System version = 1.0
CVSS3 Score: 9.8 - CRITICAL
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | NONE | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | HIGH | HIGH | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
bug_report/SQLi.md at main · 19FF/bug_report · GitHub | github.com text/html |
![]() |
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
Login required | vuldb.com text/html Inactive LinkNot Archived |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Automatic Question Paper Generator System Project | Automatic Question Paper Generator System | 1.0 | All | All | All |
- cpe:2.3:a:automatic_question_paper_generator_system_project:automatic_question_paper_generator_system:1.0:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-1474 | 2023-03-17 16:38:21 |