Skip to content

Latest commit

 

History

History
37 lines (26 loc) · 1.89 KB

CVE-2024-22909.md

File metadata and controls

37 lines (26 loc) · 1.89 KB

CVE-2024-22909 : Online-Exam-System - Cross-Site-Scripting

References:

Description:

Onlie Exam System is vulnerable to Cross-Site Scripting via the 'question' parameter at "http://localhost/exam/admin/quesadd.php" Online Exam System is vulnerable to a cross-site scripting vulnerability because it fails to adequately sanitize user-supplied data. An attacker could exploit this issue to run arbitrary scripting code in the browser of an unsuspecting user in the context of the affected site. This could allow an attacker to steal cookie-based authentication credentials and launch other attacks.

Proof of Concept:

Admin Session :

Ekran görüntüsü 2024-01-12 025248

Ekran görüntüsü 2024-01-12 025311

Student Session :

Ekran görüntüsü 2024-01-12 025450