Easy Test Project maintains a narrowly scoped testing utility focused on the Easy Test product, with a vulnerability profile centered on application-layer security controls. The observed weakness classes—SQL injection, improper authorization, and unrestricted file uploads—reflect common input-validation and access-control gaps in web-facing testing tools. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easy Test Project over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-43437HIGH The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to acce | Jan 3, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-43436HIGH The File Upload function of EasyTest has insufficient filtering for special characters and file type. A remote attacker authenticated as a general user can upload and execute arbit | Jan 3, 2023 | 8.8 | 28 | NO | NO |
CVE-2022-43438HIGH The Administrator function of EasyTest has an Incorrect Authorization vulnerability. A remote attacker authenticated as a general user can exploit this vulnerability to bypass the | Jan 3, 2023 | 8.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easy Test Project.
Media articles that mention a CVE ID that affects a product developed by Easy Test Project — matched by CVE ID, not by vendor name.