CVE-2021-42334 describes SQL injection vulnerabilities within the huaju easytest_online_learning_test_platform. An authenticated attacker, with user privileges, can inject SQL commands into the elective course management page parameters. This allows for full database access and administrator permissions, posing a high risk with a CVSS score of 8.8. While the vulnerability is severe, there is no evidence of active exploitation, public exploit code, or significant community discussion surrounding it.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1705CPE matchmatch criteria | cpe:2.3:a:huaju:easytest_online_learning_test_platform:1705:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.