Eclass develops a learning management platform centered on its Eclass IP product, with observed vulnerabilities clustering around access-control and input-handling weaknesses. The recurring issues—including improper access control, forced browsing, path traversal, and SQL injection—reflect the authentication and data-validation challenges common to web-based educational platforms. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Eclass over time
Signals from CVEs in this vendor scope (3 CVEs).
3 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-9885CRITICAL eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter. | Jul 25, 2019 | 9.8 | 25 | NO | NO |
CVE-2019-9884CRITICAL eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page. | Jul 25, 2019 | 9.8 | 25 | NO | NO |
CVE-2019-9886HIGH Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1. | Jul 11, 2019 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (3 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Eclass.
Media articles that mention a CVE ID that affects a product developed by Eclass — matched by CVE ID, not by vendor name.