Critical SQL Injection Vulnerability Discovered in Online Examination System
A recently identified vulnerability, CVE-2023-45111, has been discovered in the Online Examination System v1.0. This security flaw, known as Unauthenticated SQL Injection, can potentially expose sensitive data, posing a significant risk to users.
Vulnerability Details
The 'email' parameter of the feed.php resource in the Online Examination System v1.0 does not validate characters received, allowing unfiltered data to be sent directly to the database. This lack of validation opens the door for attackers to manipulate the SQL queries, potentially leading to data theft or system compromise.
CVSS Scores and Vector Strings
CVSS Version 4.0
The Common Vulnerability Scoring System (CVSS) Version 4.0 has assigned a base score of 9.8, classifying this vulnerability as CRITICAL. The attack vector is network (N), the attack complexity is low (L), and the privileges required are none (N). The scope is unchanged (U), the confidentiality impact is high (H), the integrity impact is high (H), and the availability impact is high (H).
CVSS Version 3.x
CVSS Version 3.x assigns a base score of 9.8 as well, with the same attack vector (N), complexity (L), and privileges required (N). However, the scope (U) and the impact on confidentiality, integrity, and availability are all rated as high (H).
Affected Software and Solutions
The Online Examination System v1.0 is the software configuration known to be affected by this vulnerability. Users are advised to update to the latest version to mitigate the risk.
Relevance to North East India and India
Online examination systems are increasingly being adopted in educational institutions across India, including North East India. The discovery of this critical vulnerability underscores the importance of cybersecurity in the digital transformation of the education sector. It is crucial for institutions to regularly update their software and implement robust security measures to protect sensitive data.
Conclusion
The Unauthenticated SQL Injection vulnerability in the Online Examination System v1.0 poses a significant risk to users. Institutions are urged to update their software and implement robust security measures to protect sensitive data. As digital transformation continues, it is essential to prioritize cybersecurity to ensure the safety and integrity of our data.