CVE-2024-43776: high-severity vulnerability in Huachu Digital Technology Ltd.
Huachu Easytest Online Learning Test Platform - SQL Injection
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.5%
exploitation probability
0.5%top 61% of all CVEs
observed exploitation
nono source reports it
SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Affected products
Huachu Digital Technology Ltd. · Easytest Online Test PlatformRelated CVEs — Huachu Digital Technology Ltd.
In the same product, most dangerous first.
CVE-2024-7871HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43773CRITICALHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43772CRITICALHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43775HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43774HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%
References
https://zuso.ai/advisory/za-2024-09