A SQL injection vulnerability in "/admin/quizquestion.php" in Kashipara Online Exam System v1.0 allows remote attackers to execute arbitrary SQL commands via the "eid" parameter.
References
| Link | Resource |
|---|---|
| https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Online%20Exam%20System%20v1.0/SQL%20Injection.pdf | Exploit Third Party Advisory |
| https://www.kashipara.com/project/php/3/online-exam-php-project-source-code-download | Product |
Configurations
History
19 Nov 2025, 12:44
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Jayesh online Exam System
Jayesh |
|
| Summary |
|
|
| References | () https://github.com/takekaramey/CVE_Writeup/blob/main/Kashipara/Online%20Exam%20System%20v1.0/SQL%20Injection.pdf - Exploit, Third Party Advisory | |
| References | () https://www.kashipara.com/project/php/3/online-exam-php-project-source-code-download - Product | |
| CPE | cpe:2.3:a:jayesh:online_exam_system:1.0:*:*:*:*:*:*:* |
13 Aug 2024, 01:13
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
12 Aug 2024, 13:41
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-08-12 13:38
Updated : 2025-11-19 12:44
NVD link : CVE-2024-40479
Mitre link : CVE-2024-40479
CVE.ORG link : CVE-2024-40479
JSON object : View
Products Affected
jayesh
- online_exam_system
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
