9.1
/ 10
CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Description
A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.
AI Analysis
SQL Injection vulnerability in Kashipara Online Exam System V1.0 allowing remote attackers to execute arbitrary SQL commands
Basic Information
ID
CVE-2025-51567
Source
mitre
Published
Jan 12, 2026 at 00:00
Modified
Jan 12, 2026 at 20:06
Affected Product
Vendor
Kashipara
Product
Kashipara Online Exam System
Version
V1.0
Affected Versions
n/a n/a n/a
CWE Classification
AI Assessment
AI Score
9.1 / 10
AI Severity
Critical
Vendor
Kashipara
Product
Kashipara Online Exam System
Version
V1.0