Efront
Vendor:
First CVE: Aug 21, 2009 · Active for 16 years
12
Total CVEs
More Total CVEs than 90% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Efront over time
Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2009
16 years ago
Most Recent CVE
Feb 5, 2018
3,091 days ago
CVE Severity & Scoring
Efront12 CVEs
17%
75%
8%
All CVEs352,231 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (25.0%)
Unknown9 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (25.0%)
High0 (0.0%)
Unknown9 (75.0%)
User Interaction
None3 (25.0%)
Unknown9 (75.0%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (75.0%)
Top CVEs
Signals from CVEs in this product scope (12 CVEs).
12 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2010-1918HIGH SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter. | May 12, 2010 | 7.5 | 29 | NO | YES |
CVE-2010-1003MEDIUM Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a | Mar 19, 2010 | 6.8 | 28 | NO | YES |
CVE-2009-3660MEDIUM PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP co | Oct 11, 2009 | 6.8 | 28 | NO | YES |
CVE-2008-7026MEDIUM Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an | Aug 21, 2009 | 6.8 | 28 | NO | YES |
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script | Dec 21, 2013 | 3.5 | 24 | NO | YES |
CVE-2014-4033MEDIUM Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via | Jun 11, 2014 | 4.3 | 22 | NO | YES |
CVE-2012-4269MEDIUM Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachme | Aug 13, 2012 | 6.0 | 19 | NO | NO |
CVE-2012-6515MEDIUM eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, whic | Jan 24, 2013 | 5.0 | 18 | NO | NO |
CVE-2015-4461MEDIUM Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter. | Feb 5, 2018 | 6.5 | 17 | NO | NO |
CVE-2015-4463MEDIUM The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file | Jul 25, 2017 | 6.5 | 17 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (12 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
50.0% of CVEs· 91st percentile
Social Chatter
Signals from CVEs in this product scope (12 CVEs).
Media Mentions
Signals from CVEs in this product scope (12 CVEs).
Top CNAs Publishing CVEs For Efront
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 3.6.14.4 | 1 | 4.3 | 3.3% | 0 | 1 |
| 3.6.14 | 1 | 3.5 | 2.6% | 0 | 1 |
| 3.6.11 | 3 | 4.8 | 1.5% | 0 | 0 |
| 3.6.10 | 1 | 5.0 | 1.5% | 0 | 0 |
| 3.6.1 | 1 | 7.5 | 1.1% | 0 | 1 |
| 3.6 | 1 | 7.5 | 1.1% | 0 | 1 |
| 3.5.5 | 2 | 7.2 | 3.1% | 0 | 2 |
| 3.5.4 | 2 | 7.2 | 3.1% | 0 | 2 |
| 3.5.3 | 2 | 7.2 | 3.1% | 0 | 2 |
| 3.5.2 | 2 | 7.2 | 3.1% | 0 | 2 |
| 3.5.1 | 3 | 7.0 | 2.7% | 0 | 3 |
| 3.5.0 | 4 | 7.0 | 2.7% | 0 | 4 |
| 3.1.4 | 3 | 7.0 | 2.6% | 0 | 3 |
| 3.1.3 | 3 | 7.0 | 2.6% | 0 | 3 |
| 3.1.2 | 3 | 7.0 | 2.6% | 0 | 3 |
| 3.1.0 | 3 | 7.0 | 2.6% | 0 | 3 |