nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47902 CVE-2021-47902
HIGH
Testa Online Test Management System 3.4.7 - 'q' SQL Injection
Record summary
CVE-2021-47902 has a selected CVSS score of 8.8 (high); EIP currently links 1 catalogued exploit.
Description
Testa Online Test Management System 3.4.7 contains a SQL injection vulnerability that allows attackers to manipulate database queries through the 'q' search parameter. Attackers can inject malicious SQL code in the search field to extract database information, potentially accessing sensitive user or system data.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 27, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
Testa Online Test Management SystemBrowse Testa / Testa Online Test Management System | CVE List | 3.4.7 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBTesta Online Test Management System 3.4.7 - 'q' SQL InjectionExploitDB exploitby Ultra Security TeamNot analyzed1 file
References
4Archived Vendor Homepageproduct
https://web.archive.org/web/20220406031253/https://testa.cc ExploitDB-49194exploit
https://www.exploit-db.com/exploits/49194 VulnCheck Advisory: Testa Online Test Management System 3.4.7 - 'q' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/testa-online-test-management-system-q-sql-injection