PT-2024-30644 · Unknown · Easytest Online Test Platform

Cheng Ying Hsieh

+1

·

Published

2024-09-01

·

Updated

2024-09-04

·

CVE-2024-43772

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Easytest Online Test Platform versions prior to ver.24E01
Description The issue allows remote attackers to execute arbitrary SQL commands via the uid parameter in the download student learning course function. This enables attackers to manipulate the database, potentially leading to unauthorized data access or modification.
Recommendations For versions prior to ver.24E01, as a temporary workaround, consider restricting access to the download student learning course function until a patch is available. Avoid using the uid parameter in the affected function to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-43772

Affected Products

Easytest Online Test Platform