CVE-2023-3059
Last modified
CVE-2023-3059 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/update_s6.php. EPSS estimates a 0.74% chance of exploitation in the next 30 days.
Description
A vulnerability, which was classified as critical, was found in SourceCodester Online Exam Form Submission 1.0. This affects an unknown part of the file /admin/update_s6.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The identifier VDB-230565 was assigned to this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Online Exam Form Submission Project | Online Exam Form Submission | 1.0 |
References
- https://vuldb.com/?ctiid.230565Third Party Advisory
- https://vuldb.com/?id.230565Third Party Advisory
- https://vuldb.com/?ctiid.230565Third Party Advisory
- https://vuldb.com/?id.230565Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3059?
How severe is CVE-2023-3059?
How do I fix CVE-2023-3059?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-30584A vulnerability has been discovered in Node.js version 20, s…7.7
- CVE-2023-30585A vulnerability has been identified in the Node.js (.msi ver…7.5
- CVE-2023-30586A privilege escalation vulnerability exists in Node.js 20 th…7.5
- CVE-2023-30587A vulnerability in Node.js version 20 allows for bypassing r…7.5
- CVE-2023-30588When an invalid public key is used to create an x509 certifi…5.3
- CVE-2023-30589The llhttp parser in the http module in Node v20.2.0 does no…7.5
- CVE-2023-30590The generateKeys() API function returned from crypto.createD…7.5
- CVE-2023-30591Denial-of-service in NodeBB <= v2.8.10 allows unauthenticate…7.5
- CVE-2023-3060A vulnerability has been found in code-projects Agro-School …5.4
- CVE-2023-30601Privilege escalation when enabling FQL/Audit logs allows use…7.8
- CVE-2023-30602Hitron Technologies CODA-5310’s Telnet function transfers se…7.5
- CVE-2023-30603Hitron Technologies CODA-5310 Telnet function with the defau…9.8
Are you affected by CVE-2023-3059?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
