QSearchQSearch

CVE-2021-42333

8.8 HIGH

The Easytest contains SQL injection vulnerabilities

Published: 2021-10-15 · Last updated: 2026-06-17

Severity and scoring

CVSS
8.8 HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-89

Affected products

VendorProduct
huajueasytest_online_learning_test_platform

Description

The Easytest contains SQL injection vulnerabilities. After obtaining user’s privilege, remote attackers can inject SQL commands into the parameters of the learning history page to access all database and obtain administrator permissions.

Source: NVD

References

Related CVEs

Same vendor

  • CVE-2021-42336 The learning history page of the Easytest is vulnerable by permission bypass (4.3 MEDIUM)
  • CVE-2021-42335 Easytest bulletin board management function of online learning platform does not filter special characters (5.4 MEDIUM)
  • CVE-2021-42334 The Easytest contains SQL injection vulnerabilities (8.8 HIGH)

Same CWE

  • CVE-2026-52715 Unauthenticated SQL Injection in GEO my WordPress <= 4.5.5 versions (9.3 CRITICAL)
  • CVE-2026-52712 Subscriber SQL Injection in Attendance Manager <= 0.6.2 versions (7.6 HIGH)
  • CVE-2026-49772 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Liquid Web / StellarWP The Events C... (9.3 CRITICAL)
  • CVE-2026-39581 Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions (8.5 HIGH)
  • CVE-2026-39574 Unauthenticated SQL Injection in InPost Gallery <= 2.1.4.6 versions (9.3 CRITICAL)