Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-40230 | The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data. |
Wed, 13 Nov 2024 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-13T20:58:24.728Z
Reserved: 2023-06-21T00:00:00.000Z
Link: CVE-2023-36256
Updated: 2024-08-02T16:45:56.237Z
Status : Modified
Published: 2023-07-07T18:15:09.693
Modified: 2024-11-21T08:09:27.680
Link: CVE-2023-36256
No data.
OpenCVE Enrichment
No data.
EUVD