huaju CVE Vulnerabilities & CVE List (4)

Products (CPE): — CVEs: 4

huaju vulnerability overview

Aggregates CVE and security vulnerability intelligence across all huaju-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk sql injection, vendor risk cross-site scripting, and vendor risk path handling and related problems; some flaws may lead to vendor impact data exposure and vendor impact file overwrite.

Vulnerability distribution trend (last 24 months)

Showing 14 of 4 CVEs
«« First « Prev Page 1 / 1 Next »
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2021-42336 The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s account information except password by crafting URL parameters. [email protected] 4.3 0.08% 2021-10-15 2024-11-21
CVE-2021-42335 Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack. [email protected] 5.4 0.06% 2021-10-15 2024-11-21
CVE-2021-42334 The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course management page to obtain all database and administrator permissions. [email protected] 8.8 0.24% 2021-10-15 2024-11-21
CVE-2021-42333 The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions. [email protected] 8.8 0.24% 2021-10-15 2024-11-21
«« First « Prev Page 1 / 1 Next »
cvelogic Threat Intelligence