Back to all
2024-09-02

Huachu Easytest Online Learning Test Platform - SQL Injection

ZUSOART ID
ZA-2024-07
CVE ID
CVE-2024-43774
Vulnerability Type
CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVSS 4.0 Base
8.7
Description

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.

Vendor
Huachu Digital Technology Ltd.
Product
Category
Version affected
Easytest Online Test Platform
ver.24E01 and earlier
Mitigations

Contact Huachu Digital Technology for version updates.

Release date
2024-09-02
Credit

Cheng Ying Hsieh (Vance Hsieh) of ZUSO ART