Medium severity6.5NVD Advisory· Published Jul 7, 2023· Updated Jun 17, 2026
CVE-2023-36256
CVE-2023-36256
Description
The Online Examination System Project 1.0 version is vulnerable to Cross-Site Request Forgery (CSRF) attacks. An attacker can craft a malicious link that, when clicked by an admin user, will delete a user account from the database without the admin's consent. The email of the user to be deleted is passed as a parameter in the URL, which can be manipulated by the attacker. This could result in a loss of data.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:a:online_examination_system_project:online_examination_system:1.0:*:*:*:*:*:*:*
- Online Examination System Project/Online Examination System Projectdescription
- Range: = 1.0
Patches
Vulnerability mechanics
References
2- www.exploit-db.com/exploits/51511nvdExploitThird Party AdvisoryVDB Entry
- www.hackersnotes.com/blog/pentest/online-examination-system-project-1-0-cross-site-request-forgery-csrf/nvdExploitThird Party Advisory
News mentions
0No linked articles in our index yet.