CVE-2024-40480

CRITICAL

Kashipara Online Exam System <1.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

A Broken Access Control vulnerability was found in /admin/update.php and /admin/dashboard.php in Kashipara Online Exam System v1.0, which allows remote unauthenticated attackers to view administrator dashboard and delete valid user accounts via the direct URL access.

Scores

CVSS v3 9.8
EPSS 0.0053
EPSS Percentile 41.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-284
Status published
Products (1)
jayesh/online_exam_system 1.0
Published Aug 12, 2024
Tracked Since Feb 18, 2026