vendor:
Simple Online College Entrance Exam System
by:
Amine Ismail
7.5
CVSS
HIGH
Unauthenticated Admin Creation
284
CWE
Product Name: Simple Online College Entrance Exam System
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:sourcecodester:simple_online_college_entrance_exam_system
Platforms Tested: Windows 10, Kali Linux
2021
Simple Online College Entrance Exam System 1.0 – Unauthenticated Admin Creation
An unauthenticated admin creation vulnerability exists in Simple Online College Entrance Exam System 1.0. An attacker can send a POST request to the Actions.php page with the parameters id, fullname, username, and type to create an admin user. A proof-of-concept (PoC) to create an admin user named exploitdb and password exploitdb is provided.
Mitigation:
Ensure that authentication is required for all administrative functions.