vendor:
Exam Reviewer Management System
by:
Juli Agarwal
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: Exam Reviewer Management System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 10, Kali Linux
2022
Exam Reviewer Management System 1.0 – ‘id’ SQL Injection
The 'id' parameter in Exam Reviewer Management System web application is vulnerable to SQL Injection.
Mitigation:
The vendor should sanitize and validate user input to prevent SQL Injection attacks.