Efrontlearning

    Dashboard / Vendors

    Products: 2
    Vulnerabilities: 13
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    10
    Medium Level Threats
    2
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2015-4461

    Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.

    Last Modified: Nov 21, 2024
    Published: Feb 05, 2018

    CVE-2015-4462

    Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

    Last Modified: Apr 20, 2025
    Published: Jul 25, 2017

    CVE-2015-4463

    The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.

    Last Modified: Apr 20, 2025
    Published: Jul 25, 2017

    CVE-2014-4033

    Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via the surname parameter to student.php.

    Last Modified: Apr 12, 2025
    Published: Jun 11, 2014

    CVE-2013-7194

    Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.

    Last Modified: Apr 11, 2025
    Published: Dec 21, 2013
    Items Per Page
    Efrontlearning Vulnerabilities & Security CVEs | CVE-DB