HIGH
BitZoom 1.0 SQL Injection via rollno Parameter
Published Mar 6, 2026
8.8
HIGHCVSS 4.0
EPSS 0.26%
Description
BitZoom 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rollno and username parameters in forgot.php and login.php. Attackers can submit crafted POST requests with SQL UNION statements to extract database schema information and table contents from the application database.
Affected products
-
- Version 1.0StatusaffectedConstraints-
- Version
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21618 Advisory
- https://www.exploit-db.com/exploits/45862 exploit
- https://www.vulncheck.com/advisories/bitzoom-sql-injection-via-rollno-parameter third-party-advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2018-21618 | Advisory | |
| https://www.exploit-db.com/exploits/45862 | exploit | |
| https://www.vulncheck.com/advisories/bitzoom-sql-injection-via-rollno-parameter | third-party-advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Mar 6, 2026
Updated Mar 9, 2026
Reserved Mar 6, 2026
Link CVE-2018-25163
CISA Vulnrichment
Updated Mar 9, 2026
ENISA EUVD
EUVD-2018-21618 Assigner VulnCheck
Published Mar 6, 2026
Updated Mar 9, 2026
Exploited since n/a
Link EUVD-2018-21618