CVE-2024-43772

CRITICAL

Easytest Online Test Platform < 24e01 - SQL Injection via UID Parameter

Title source: llm
STIX 2.1

Description

SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://zuso.ai/advisory/za-2024-05

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 38.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
easytest/easytest_online_test_platform < 24e01
Published Sep 02, 2024
Tracked Since Feb 18, 2026