Описание
The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.
Ссылки
- Third Party Advisory
- Third Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:huaju:easytest_online_learning_test_platform:1705:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00238
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89
Связанные уязвимости
github
больше 3 лет назад
The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.
EPSS
Процентиль: 47%
0.00238
Низкий
8.8 High
CVSS3
6.5 Medium
CVSS2
Дефекты
CWE-89