CVE-2021-47902

HIGH

Testa Online Test Management System <3.4.7 - SQL Injection

Title source: llm
STIX 2.1

Description

Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.

Exploits (1)

exploitdb WORKING POC
by Ultra Security Team · textwebappsmultiple
https://www.exploit-db.com/exploits/49194

Scores

CVSS v3 8.2
EPSS 0.0005
EPSS Percentile 15.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
Testa/Testa Online Test Management System 3.4.7
Published Jan 27, 2026
Tracked Since Feb 18, 2026