go to Content
:::

TWCERT/CC Taiwan Computer Emergency Response Team/Coordination Center

:::
Date:
Font-stze:

Huachu Digital Technology Co.,Ltd. Easytest - Stored XSS

TVN ID TVN-202110007
CVE ID CVE-2021-42335
CVSS 5.4 (Medium)
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Affected Products Huachu Digital Technology Co.,Ltd. Easytest ver.1705
Description Easytest bulletin board management function of online learning platform does not filter special characters. After obtaining a user’s privilege, remote attackers can inject JavaScript and execute stored XSS attack.
Solution Update Easytest to version 2100
Credit Eric Wang
Public Date 2021-10-15
Top