CVE-2025-51567: Jayesh Online Exam System

Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.

A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.

Affected products

  • Jayesh Online Exam System: version 1.0 only

Published 2026-01-12. Last modified 2026-06-17.