Back

HIGH

BitZoom 1.0 SQL Injection via rollno Parameter

Published Mar 6, 2026

Description

BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 6, 2026
Updated Mar 9, 2026
Reserved Mar 6, 2026
CISA Vulnrichment
Updated Mar 9, 2026
NVD
Status Deferred
Modified Oct 7, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner VulnCheck
Published Mar 6, 2026
Updated Mar 9, 2026
Exploited since n/a
EUVD-2018-21618