Unrated severityNVD Advisory· Published Jul 5, 2026· Updated Jul 6, 2026
code-projects Online Examination Quiz Creation Feature update.php sql injection
CVE-2026-14706
Description
A vulnerability was identified in code-projects Online Examination 1.0. This affects an unknown part of the file /update.php?q=addquiz of the component Quiz Creation Feature. The manipulation of the argument name/total/right/wrong/time/tag/desc leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might be used.
Affected products
1- Range: = 1.0
Patches
Vulnerability mechanics
References
6- github.com/zzzxc643/CVE1/blob/main/project1/vul3.mdmitreexploit
- vuldb.com/cve/CVE-2026-14706mitrethird-party-advisory
- vuldb.com/submit/847386mitrethird-party-advisory
- code-projects.orgmitreproduct
- vuldb.com/vuln/376302mitrevdb-entrytechnical-description
- vuldb.com/vuln/376302/ctimitresignaturepermissions-required
News mentions
0No linked articles in our index yet.