CVE-2025-51567: Jayesh Online Exam System
Critical severity, CVSS 9.1. EPSS: 0.4% chance of exploitation in the next 30 days.
A SQL Injection was found in the /exam/user/profile.php page of kashipara Online Exam System V1.0, which allows remote attackers to execute arbitrary SQL command to get unauthorized database access via the rname, rcollage, rnumber, rgender and rpassword parameters in a POST HTTP request.
Affected products
- Jayesh Online Exam System: version 1.0 only
Published 2026-01-12. Last modified 2026-06-17.