Executive brief
A vulnerability exists in the Online Examination system, a web application used for managing and conducting digital tests. An attacker can exploit this flaw to bypass the administrator login screen, potentially gaining full access to exam data, student information, and system settings. This could lead to unauthorized changes to test results or the theft of sensitive user data.
Technical details
A SQL injection vulnerability exists in the `head.php` file of code-projects Online Examination 1.0. The application fails to sanitize the `uname` and `password` POST parameters before concatenating them into a database query used for administrator authentication. A remote, unauthenticated attacker can exploit this by sending crafted SQL payloads (such as time-based blind injection) to the `head.php?q=index.php` endpoint. Successful exploitation allows an attacker to bypass authentication, enumerate database tables, and extract sensitive information from the underlying MySQL database. A public exploit demonstrating a time-based blind injection payload has been disclosed.
Affected products
- code-projects Online Examination 1.0
Timeline
- 2026-07-05: disclosed: Public disclosure of the vulnerability and exploit details.
- 2026-07-05: advisory