← Back

Easy Test Project

easy_test_project

3 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Easy Test
easy_test

CVEs (3)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Easy Test Project
1Easy Test
Nov 21, 2024
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make AP...Show more
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, manipulate system and terminate service.Show less
1Easy Test Project
1Easy Test
Nov 21, 2024
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.
1Easy Test Project
1Easy Test
Nov 21, 2024
Jan 3, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disr...Show more
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service.Show less