A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/rank_update.php. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.
| Software | From | Fixed in |
|---|---|---|
| fabian / online_class_and_exam_scheduling_system | 1.0 | 1.0.x |