CVE Feed

    Dashboard / CVE / CVE-2020-37051

    CVE-2020-37051

    Online-Exam-System 2015 contains a time-based blind SQL injection vulnerability in the feedback form that allows attackers to extract database password hashes. Attackers can exploit the 'feed.php' endpoint by crafting malicious payload requests that use time delays to systematically enumerate user password characters.

    Published:Jan 30, 2026
    Last Modified:Mar 12, 2026
    EPS:Jan 30, 2026
    EPSS Score:0.00017
    CVSS Score:8.2

    Affected Products

    Vendor
    Nayem-howlader
    Product
    Online Exam System
    Vendor
    Sunnygkp10
    Product
    Online-exam-system
    Vendor
    Sunnygkp10
    Product
    Online-exam-system-

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High