Easytest operates an online testing platform whose vulnerability profile, despite a narrow product scope, skews strongly toward critical-severity outcomes. The recurring exposure centers on SQL injection flaws in the platform, reflecting insufficient input sanitization in database-query construction. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Easytest over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-43773CRITICAL SQL Injection in download class learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the cst | Sep 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-43772CRITICAL SQL Injection in download student learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote attackers to execute arbitrary SQL commands via the u | Sep 2, 2024 | 9.8 | 27 | NO | NO |
CVE-2024-43775HIGH SQL Injection in search course titles function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the sea | Sep 2, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-7871HIGH SQL Injection in online dictionary function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the word p | Sep 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-43776HIGH SQL Injection in mock exam function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL commands via the qlevel paramet | Sep 2, 2024 | 8.8 | 24 | NO | NO |
CVE-2024-43774HIGH SQL Injection in download personal learning course function of Easytest Online Test Platform ver.24E01 and earlier allow remote authenticated users to execute arbitrary SQL command | Sep 2, 2024 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Easytest.
Media articles that mention a CVE ID that affects a product developed by Easytest — matched by CVE ID, not by vendor name.