CVE-2022-43437

Publication date

2023-01-03 00:00:00

Family

twcert

State

PUBLISHED

Description

The Download function’s parameter of EasyTest has insufficient validation for user input. A remote attacker authenticated as a general user can inject arbitrary SQL command to access, modify or delete database.