CVE-2024-43772: fallo crítico en Huachu Digital Technology Ltd.
Huachu Easytest Online Learning Test Platform - SQL Injection
Publicada el · Actualizada el
28Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.3epss 0.5%
probabilidad de explotación
0.5%top 60% de las CVE
explotación observada
noninguna fuente lo reporta
SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the uid parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
Huachu Digital Technology Ltd. · Easytest Online Test PlatformCVEs relacionadas — Huachu Digital Technology Ltd.
En el mismo producto, de las más peligrosas a las menos.
CVE-2024-7871HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43773CRITICALHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43776HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43775HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43774HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%
Referencias
https://zuso.ai/advisory/za-2024-05