CVE-2024-43774

HIGH

Easytest Online Test Platform < 24e01 - Authenticated SQL Injection via UID Parameter

Title source: llm
STIX 2.1

Description

SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the uid parameter.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://zuso.ai/advisory/za-2024-07

Scores

CVSS v3 8.8
EPSS 0.0047
EPSS Percentile 37.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
easytest/easytest_online_test_platform < 24e01
Published Sep 02, 2024
Tracked Since Feb 18, 2026