7
I Use This!
Activity Not Available
 

Security

Vulnerabilities per Version

Learn more about BDSAs
 
 

Major Versions

1yr
3yr
5yr
10yr
All
click and drag to zoom
 
 
Security Vulnerabilities for Version:
Severities:
Type
Identifier Related Record Severity Date Published Description Versions Affected
CVE-2015-4463 Medium Jul 25, 2017 The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a c more...
3.6.13, 3.6.12, 3.6.11, 3.6.10, 3.6.9, 3.6.3, 3.6.2
CVE-2015-4462 Medium Jul 25, 2017 Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary f more...
3.6.13, 3.6.12, 3.6.11, 3.6.10, 3.6.9, 3.6.3, 3.6.2
CVE-2015-4461 Medium Feb 05, 2018 Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathn more...
3.6.13, 3.6.12, 3.6.11, 3.6.10, 3.6.9, 3.6.3, 3.6.2
CVE-2015-1559 Medium Feb 10, 2015 Multiple cross-site request forgery (CSRF) vulnerabilities in administrator.php in Epignosis eFront Open Source Edition before 3.6.15.3 build 18022 all more...
3.6.13, 3.6.12, 3.6.11, 3.6.10, 3.6.9, 3.6.3, 3.6.2
BDSA-2016-0852 Medium Oct 26, 2017 eFront is an eLearning platform written in PHP, and it is prone to remote code execution (*RCE*) in `globals.php` due to improper input handling. Proo more...