CVE-2022-43437

The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.
Configurations

Configuration 1 (hide)

cpe:2.3:a:easy_test_project:easy_test:17l18s:*:*:*:*:*:*:*

History

21 Nov 2024, 07:26

Type Values Removed Values Added
Summary
  • (es) El parámetro de la función Download de EasyTest no tiene validación suficiente para la entrada del usuario. Un atacante remoto autenticado como usuario general puede inyectar un comando SQL arbitrario para acceder, modificar o eliminar la base de datos.
References () https://www.twcert.org.tw/tw/cp-132-6829-11133-1.html - Third Party Advisory () https://www.twcert.org.tw/tw/cp-132-6829-11133-1.html - Third Party Advisory

Information

Published : 2023-01-03 03:15

Updated : 2024-11-21 07:26


NVD link : CVE-2022-43437

Mitre link : CVE-2022-43437

CVE.ORG link : CVE-2022-43437


JSON object : View

Products Affected

easy_test_project

  • easy_test
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')