Known Vulnerabilities for products from Efrontlearning
Listed below are 13 of the newest known vulnerabilities associated with the vendor "Efrontlearning".
These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.
Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2015-4463 json | The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload res... | Not Provided | 2017-07-25 | 2025-04-20 |
| CVE-2015-4462 json | Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated... | Not Provided | 2017-07-25 | 2025-04-20 |
| CVE-2015-4461 json | Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive in... | 6.5 - MEDIUM | 2018-02-05 | 2018-02-26 |
| CVE-2014-4033 json | Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remot... | Not Provided | 2014-06-11 | 2026-05-06 |
| CVE-2013-7194 json | Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote auth... | Not Provided | 2013-12-21 | 2026-04-29 |
| CVE-2012-6515 json | eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID... | Not Provided | 2013-01-24 | 2026-04-29 |
| CVE-2012-4270 json | Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or... | Not Provided | 2012-08-13 | 2026-04-29 |
| CVE-2012-4269 json | Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by upload... | Not Provided | 2012-08-13 | 2026-04-29 |
| CVE-2012-1048 json | Cross-site scripting (XSS) vulnerability in communityplusplus/www/administrator.php in eFront Community++ edition 3.6.10, and... | Not Provided | 2012-02-12 | 2026-04-29 |
| CVE-2010-1918 json | SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL comm... | Not Provided | 2010-05-12 | 2026-04-29 |
| CVE-2010-1003 json | Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attac... | Not Provided | 2010-03-19 | 2026-04-29 |
| CVE-2009-3660 json | PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabl... | Not Provided | 2009-10-11 | 2026-04-23 |
| CVE-2008-7026 json | Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attacker... | Not Provided | 2009-08-21 | 2026-04-23 |
Known software with vulnerabilities from Efrontlearning
| Type | Vendor | Product | Version |
|---|---|---|---|
| Application | Efrontlearning | Efront | 3.1.0 |