Description
The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions.
No analysis available yet.
Remediation
Vendor Solution
Update Easytest to version 2100
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29308 | The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5204-f80ad-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:17:44.540Z
Reserved: 2021-10-12T00:00:00.000Z
Link: CVE-2021-42334
No data.
Status : Modified
Published: 2021-10-15T12:15:07.890
Modified: 2024-11-21T06:27:37.707
Link: CVE-2021-42334
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD