Record summary

CVE-2021-47902 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.

Description

Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Testa Online Test Management System

Browse Testa / Testa Online Test Management System
CVE List3.4.7affected

Proofs of concept

1

Catalogued exploits

ExploitDBTesta Online Test Management System 3.4.7 - 'q' SQL InjectionExploitDB exploitby Ultra Security TeamNot analyzed1 file
ExploitDB

PoC details

References

4