Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication.
Metrics
Affected Vendors & Products
References
History
Fri, 27 Mar 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hscripts
Hscripts online Quiz Maker |
|
| Vendors & Products |
Hscripts
Hscripts online Quiz Maker |
Thu, 26 Mar 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 26 Mar 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Online Quiz Maker 1.0 contains SQL injection vulnerabilities in the catid and usern parameters that allow authenticated attackers to execute arbitrary SQL commands. Attackers can submit malicious POST requests to quiz-system.php or add-category.php with crafted SQL payloads in POST parameters to extract sensitive database information or bypass authentication. | |
| Title | Online Quiz Maker 1.0 SQL Injection via catid Parameter | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-03-26T11:39:53.997Z
Updated: 2026-03-26T13:00:10.011Z
Reserved: 2026-03-26T11:33:48.528Z
Link: CVE-2018-25207
Updated: 2026-03-26T12:59:42.965Z
Status : Awaiting Analysis
Published: 2026-03-26T12:16:05.847
Modified: 2026-03-26T15:13:15.790
Link: CVE-2018-25207
No data.