CVE-2020-37051

HIGH

Online-Exam-System 2015 - SQL Injection

Title source: llm

Description

Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.

Exploits (1)

exploitdb WORKING POC
by Gus Ralph · pythonwebappsphp
https://www.exploit-db.com/exploits/48560

Scores

CVSS v3 8.2
EPSS 0.0002
EPSS Percentile 3.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
sunnygkp10/online-exam-system- 2015
Published Jan 30, 2026
Tracked Since Feb 18, 2026