Back

HIGH

Time-Based Blind SQLi in Kodmatic Computer's Online Exam and Assessment

Published Jan 30, 2026

Description

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Kodmatic Computer Software Tourism Construction Industry and Trade Ltd. Co. Online Exam and Assessment allows SQL Injection.

This issue affects Online Exam and Assessment: through 30012026. 

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner TR-CERT
Published Jan 30, 2026
Updated Jun 5, 2026
Reserved May 14, 2025
CISA Vulnrichment
Updated Jan 30, 2026
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a