Filtered by vendor Huaju Subscriptions
Filtered by product Easytest Online Learning Test Platform Subscriptions
Total 10 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-42333 1 Huaju 1 Easytest Online Learning Test Platform 2024-09-16 8.8 High
The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.
CVE-2021-42335 1 Huaju 1 Easytest Online Learning Test Platform 2024-09-16 5.4 Medium
Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
CVE-2021-42336 1 Huaju 1 Easytest Online Learning Test Platform 2024-09-16 4.3 Medium
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.
CVE-2021-42334 1 Huaju 1 Easytest Online Learning Test Platform 2024-09-16 8.8 High
The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions.
CVE-2024-7871 2 Easytest Online Test Platform Project, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 8.8 High
SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.
CVE-2024-43776 2 Easytest, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 8.8 High
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
CVE-2024-43775 2 Easytest, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 8.8 High
SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the search parameter.
CVE-2024-43774 2 Easytest, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 8.8 High
SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.
CVE-2024-43773 2 Easytest, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 9.8 Critical
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
CVE-2024-43772 2 Easytest, Huaju 2 Easytest Online Test Platform, Easytest Online Learning Test Platform 2024-09-04 9.8 Critical
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.