VendorsEfront Learningefront3.6.11
Vulnerabilities

Efront Learning efront 3.6.11

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

3CVEs
CVE-2012-4269
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachment in a message.
Published 2012-08-13 · Modified
6.0EPSS 0.021
CVE-2012-6515
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, which reveals the installation path in an error message.
Published 2013-01-24 · Modified
5.0EPSS 0.015
CVE-2012-4270
Cross-site scripting (XSS) vulnerability in eFront 3.6.11 allows remote authenticated users to inject arbitrary web script or HTML via the subject box of a message.
Published 2012-08-13 · Modified
3.5EPSS 0.010