Record summary

CVE-2023-36256 has a selected CVSS score of 6.5 (medium); EIP currently links 1 catalogued exploit.

Description

The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Nov 13, 2024 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBOnline Examination System Project 1.0 - Cross-site request forgery (CSRF)ExploitDB exploitby Ramil MustafayevNot analyzed1 file
ExploitDB

PoC details

References

3