CVE-2020-37057

HIGH

Online-Exam-System 2015 - SQL Injection

Title source: llm
STIX 2.1

Description

Online-Exam-System 2015 contains a SQL injection vulnerability in the feedback module that allows attackers to manipulate database queries through the 'fid' parameter. Attackers can inject malicious SQL code into the 'fid' parameter to potentially extract, modify, or delete database information.

Exploits (1)

exploitdb WORKING POC
by Berk Dusunur · textwebappsphp
https://www.exploit-db.com/exploits/48529

Scores

CVSS v3 8.2
EPSS 0.0002
EPSS Percentile 6.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
sunnygkp10/online-exam-system- 2015
Published Jan 30, 2026
Tracked Since Feb 18, 2026