CVE-2021-47902

HIGH

Testa Online Test Management System <3.4.7 - SQL Injection

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-47902. PoCs published by Ultra Security Team.

AI-analyzed exploit summary This exploit demonstrates a SQL injection vulnerability in Testa Online Test Management System 3.4.7 via the 'q' parameter in a POST request. The payload uses a UNION-based SQLi to extract user information from the database.

Description

Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.

Exploits (1)

exploitdb WORKING POC
by Ultra Security Team · textwebappsmultiple
https://www.exploit-db.com/exploits/49194

This exploit demonstrates a SQL injection vulnerability in Testa Online Test Management System 3.4.7 via the 'q' parameter in a POST request. The payload uses a UNION-based SQLi to extract user information from the database.

Classification
Working Poc 90%
Attack Type
Sqli
Complexity
Trivial
Reliability
Reliable
Target: Testa Online Test Management System v3.4.7
Auth required
Prerequisites: Valid session cookie (PHPSESSID, testa_user2) · Access to the search exams functionality
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (3)

Core 3

Scores

CVSS v3 8.2
EPSS 0.0024
EPSS Percentile 14.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Testa/Testa Online Test Management System 3.4.7
Published Jan 27, 2026
Tracked Since Feb 18, 2026