Huaju's vulnerability footprint is centered on its EasyTest Online Learning Test Platform, a web-based educational assessment application where the observed weaknesses cluster around input-handling and access-control issues. The recurring exposure includes SQL injection, improper authorization, and cross-site scripting vulnerabilities typical of web application development, alongside miscellaneous findings; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Huaju over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-42334HIGH The Easytest contains SQL injection vulnerabilities. After obtaining a user’s privilege, remote attackers can inject SQL commands into the parameters of the elective course managem | Oct 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-42333HIGH The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to | Oct 15, 2021 | 8.8 | 27 | NO | NO |
CVE-2021-42335MEDIUM Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScri | Oct 15, 2021 | 5.4 | 19 | NO | NO |
CVE-2021-42336MEDIUM The learning history page of the Easytest is vulnerable by permission bypass. After obtaining a user’s permission, remote attackers can access other users’ and administrator’s acco | Oct 15, 2021 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Huaju.
Media articles that mention a CVE ID that affects a product developed by Huaju — matched by CVE ID, not by vendor name.