Junglewise Threat Intelligence

CVE-2025-4688: BGS Interactive SINAV.LINK SQL injection in Exam Result Module

CVE-2025-4688 · Severity: critical · CVSS 9.8 · Published 2025-09-16

Executive brief

A critical security vulnerability has been identified in the BGS Interactive SINAV.LINK Exam Result Module, a system used for managing and displaying examination results. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially allowing them to steal sensitive student information, modify exam scores, or disrupt the availability of the service. This issue can be exploited remotely without requiring any login credentials.

Technical details

A SQL injection vulnerability (CWE-89) exists in the BGS Interactive SINAV.LINK Exam Result Module due to improper neutralization of special elements used in SQL commands. The flaw is located within the Exam Result Module and can be exploited by a remote, unauthenticated attacker via specially crafted network requests. Successful exploitation allows for full read and write access to the database, potentially leading to complete compromise of data confidentiality, integrity, and system availability. The issue is addressed in version 1.2 and later.

Affected products

  • BGS Interactive SINAV.LINK Exam Result Module before 1.2

Timeline

  • 2025-09-16: disclosed
  • 2025-09-16: advisory

References