Description
The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters.
No analysis available yet.
Remediation
Vendor Solution
Update Easytest to version 2100
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-29310 | The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters. |
References
| Link | Providers |
|---|---|
| https://www.twcert.org.tw/tw/cp-132-5205-1de5a-1.html |
|
History
No history.
Status: PUBLISHED
Assigner: twcert
Published:
Updated: 2024-09-16T16:33:19.781Z
Reserved: 2021-10-12T00:00:00.000Z
Link: CVE-2021-42336
No data.
Status : Modified
Published: 2021-10-15T12:15:08.010
Modified: 2024-11-21T06:27:37.980
Link: CVE-2021-42336
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD