Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.
History

Tue, 03 Feb 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Sunnygkp10
Sunnygkp10 online-exam-system
Vendors & Products Sunnygkp10
Sunnygkp10 online-exam-system

Mon, 02 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 30 Jan 2026 22:30:00 +0000

Type Values Removed Values Added
Description Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.
Title Online-Exam-System 2015 - 'feedback' SQL Injection
Weaknesses CWE-89
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-02-02T20:10:12.073Z

Reserved: 2026-01-28T18:18:30.525Z

Link: CVE-2020-37051

cve-icon Vulnrichment

Updated: 2026-02-02T20:10:08.311Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-30T23:16:10.963

Modified: 2026-02-03T16:44:36.630

Link: CVE-2020-37051

cve-icon Redhat

No data.