Junglewise Threat Intelligence

CVE-2025-4686: Kodmatic Online Exam and Assessment SQL injection

CVE-2025-4686 · Severity: high · CVSS 8.6 · Published 2026-01-30

Executive brief

Kodmatic's Online Exam and Assessment software contains a critical security flaw that allows unauthorized individuals to manipulate the application's database. This software is used for managing and delivering digital examinations. An attacker could exploit this to access sensitive student data, modify exam results, or disrupt the availability of the testing platform.

Technical details

An SQL injection vulnerability exists in Kodmatic Online Exam and Assessment through version 30012026 due to improper neutralization of special elements used in SQL commands (CWE-89). The vulnerability is reachable over the network without authentication (AV:N/AC:L/PR:N/UI:N). An attacker can exploit this flaw to perform unauthorized data retrieval, modify database records, or cause a denial-of-service condition on the database server. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.

Affected products

  • Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment through 30012026

Timeline

  • 2026-01-30: advisory: Initial disclosure by TR-CERT (USOM)
  • 2026-01-30: disclosed: NVD publication date

References