CVE-2025-14668 HIGH
← Quay lại danh sách
Dịch vụ / phần mềm liên quan:
Chưa phân loại — không khớp danh sách dịch vụ/phần mềm đang theo dõi (xem/thêm ở
internal/cve/categories.go), hoặc NVD chưa cung cấp đủ dữ liệu vendor/sản phẩm cho CVE này.
Mô tả
A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.
Chi tiết
| Trạng thái | Modified |
| Điểm CVSS | 7.3 (v3.1) |
| Vector CVSS | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
| Ngày công bố | 00:15 15/12/2025 |
| Ngày cập nhật | 17:10 28/09/2026 |
| Nguồn dữ liệu | nvd |
CWE
Sản phẩm bị ảnh hưởng
| Vendor | Sản phẩm | Khoảng phiên bản |
|---|---|---|
| campcodes | advanced_online_examination_system | - |
Tài liệu tham khảo
- [cna@vuldb.com] https://github.com/gravity123123/CVE/issues/1 (Exploit, Issue Tracking, Third Party Advisory)
- [cna@vuldb.com] https://vuldb.com/?ctiid.336400 (Permissions Required, VDB Entry)
- [cna@vuldb.com] https://vuldb.com/?id.336400 (Third Party Advisory, VDB Entry)
- [cna@vuldb.com] https://vuldb.com/?submit.714806 (Third Party Advisory, VDB Entry)
- [cna@vuldb.com] https://www.campcodes.com/ (Product)
Lịch sử thay đổi
| Thời gian | Loại | Trường | Giá trị cũ | Giá trị mới |
|---|---|---|---|---|
| 17:17 28/09/2026 | CREATED | cve | HIGH |