CVE-2024-7871

HIGH

Easytest Online Test Platform < 24e01 - Authenticated SQL Injection via Word Parameter

Title source: llm
STIX 2.1

Description

SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word parameter.

References (1)

Core 1
Core References
Third Party Advisory third-party-advisory
https://zuso.ai/advisory/za-2024-04

Scores

CVSS v3 8.8
EPSS 0.0052
EPSS Percentile 40.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-89
Status published
Products (1)
easytest/easytest_online_test_platform < 24e01
Published Sep 02, 2024
Tracked Since Feb 18, 2026