<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2018-25207 — CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2018-25207/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata — refreshed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 26 Mar 2026 12:16:05 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2018-25207/feed.xml" rel="self" type="application/rss+xml"/><item><title>Online Quiz Maker 1.0 SQL Injection Vulnerability (CVE-2018-25207)</title><link>https://feed.craftedsignal.io/briefs/2026-03-online-quiz-maker-sqli/</link><pubDate>Thu, 26 Mar 2026 12:16:05 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-03-online-quiz-maker-sqli/</guid><description>Online Quiz Maker 1.0 is vulnerable to SQL injection via the catid and usern parameters, allowing authenticated attackers to execute arbitrary SQL commands by submitting malicious POST requests to quiz-system.php or add-category.php.</description><content:encoded><![CDATA[<p>Online Quiz Maker 1.0 is susceptible to SQL injection vulnerabilities, specifically identified as CVE-2018-25207. The vulnerability resides in the <code>catid</code> and <code>usern</code> parameters, which can be exploited by an authenticated attacker to inject arbitrary SQL commands. The attack vector involves crafting malicious POST requests to either <code>quiz-system.php</code> or <code>add-category.php</code>. Successful exploitation of this vulnerability can lead to unauthorized access to sensitive data stored in the database…</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>sql-injection</category><category>cve-2018-25207</category><category>web-application</category></item></channel></rss>