CVEs (4)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Huaju 1Easytest Online Learning Test Platform Nov 21, 2024 Oct 15, 2021 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by craft...Show more |
1Huaju 1Easytest Online Learning Test Platform Nov 21, 2024 Oct 15, 2021 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack. |
1Huaju 1Easytest Online Learning Test Platform Nov 21, 2024 Oct 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and admi...Show more |
1Huaju 1Easytest Online Learning Test Platform Nov 21, 2024 Oct 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administr...Show more |