CVE-2024-43773: falha crítica em Huachu Digital Technology Ltd.
Huachu Easytest Online Learning Test Platform - SQL Injection
Publicada em · Atualizada em
28Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 9.3epss 0.5%
probabilidade de exploração
0.5%top 60% das CVEs
exploração observada
nãonenhuma fonte reporta
SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cstr parameter.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Produtos afetados
Huachu Digital Technology Ltd. · Easytest Online Test PlatformCVEs relacionadas — Huachu Digital Technology Ltd.
No mesmo produto, das mais perigosas para as menos.
CVE-2024-7871HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43772CRITICALHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43776HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43775HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%CVE-2024-43774HIGHHuachu Easytest Online Learning Test Platform - SQL InjectionEPSS 0.5%
Referências
https://zuso.ai/advisory/za-2024-06