Show filters
5 Total Results
Displaying 1-5 of 5
Sort by:
Attacker Value
Unknown
CVE-2024-8328
Disclosure Date: August 30, 2024 (last updated September 05, 2024)
Easy test Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary JavaScript code and perform Reflected Cross-site scripting attacks.
0
Attacker Value
Unknown
CVE-2024-8327
Disclosure Date: August 30, 2024 (last updated September 05, 2024)
Easy test
Online Learning and Testing Platform from HWA JIUH DIGITAL TECHNOLOGY does not properly validate a specific page parameter, allowing remote attackers with regular privilege to inject arbitrary SQL commands to read, modify, and delete database contents.
0
Attacker Value
Unknown
CVE-2022-43436
Disclosure Date: December 30, 2022 (last updated February 24, 2025)
The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbitrary files, to manipulate system or disrupt service.
0
Attacker Value
Unknown
CVE-2022-43437
Disclosure Date: December 30, 2022 (last updated February 24, 2025)
The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.
0
Attacker Value
Unknown
CVE-2022-43438
Disclosure Date: December 30, 2022 (last updated February 24, 2025)
The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the intended access restrictions, to make API functions calls, manipulate system and terminate service.
0