Vulnerabilities > Exam Reviewer Management System Project

DATE CVE VULNERABILITY TITLE RISK
2022-09-27 CVE-2022-40877 SQL Injection vulnerability in Exam Reviewer Management System Project Exam Reviewer Management System 1.0
Exam Reviewer Management System 1.0 is vulnerable to SQL Injection via the ‘id’ parameter.
network
low complexity
exam-reviewer-management-system-project CWE-89
critical
9.8
2022-09-27 CVE-2022-40878 Unrestricted Upload of File with Dangerous Type vulnerability in Exam Reviewer Management System Project Exam Reviewer Management System 1.0
In Exam Reviewer Management System 1.0, an authenticated attacker can upload a web-shell php file in profile page to achieve Remote Code Execution (RCE).
8.8