Efront

Vendor:

First CVE: Aug 21, 2009 · Active for 16 years

12
Total CVEs
More Total CVEs than 90% of tracked products
1.7
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
5.8
Avg CVSS
Higher Avg CVSS than 18% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Efront over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 21, 2009
16 years ago
Most Recent CVE
Feb 5, 2018
3,091 days ago

CVE Severity & Scoring

Efront12 CVEs
All CVEs352,231 CVEs
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network3 (25.0%)
Unknown9 (75.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (25.0%)
High0 (0.0%)
Unknown9 (75.0%)
User Interaction
None3 (25.0%)
Unknown9 (75.0%)
Required0 (0.0%)
Privileges Required
Low3 (25.0%)
High0 (0.0%)
None0 (0.0%)
Unknown9 (75.0%)

Top CVEs

Signals from CVEs in this product scope (12 CVEs).

12 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL commands via the chatrooms_ID parameter.
May 12, 20107.529NOYES
Directory traversal vulnerability in www/editor/tiny_mce/langs/language.php in eFront 3.5.x through 3.5.5 allows remote attackers to include and execute arbitrary local files via a
Mar 19, 20106.828NOYES
PHP remote file inclusion vulnerability in libraries/database.php in Efront 3.5.4 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP co
Oct 11, 20096.828NOYES
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote attackers to execute arbitrary code by uploading a file with an
Aug 21, 20096.828NOYES
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script
Dec 21, 20133.524NOYES
Cross-site scripting (XSS) vulnerability in libraries/includes/personal/profile.php in Epignosis eFront 3.6.14.4 allows remote attackers to inject arbitrary web script or HTML via
Jun 11, 20144.322NOYES
Unrestricted file upload vulnerability in eFront 3.6.11 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension via an attachme
Aug 13, 20126.019NONO
eFront 3.6.10, 3.6.11 build 15059, and earlier allows remote attackers to obtain sensitive information via invalid courses_ID parameter in the lesson_info module to index.php, whic
Jan 24, 20135.018NONO
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
Feb 5, 20186.517NONO
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file
Jul 25, 20176.517NONO

Exploit Exposure

Signals from CVEs in this product scope (12 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
6 CVEs
50.0% of CVEs· 91st percentile

Social Chatter

Signals from CVEs in this product scope (12 CVEs).

Media Mentions

Signals from CVEs in this product scope (12 CVEs).

Top CNAs Publishing CVEs For Efront

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
3.6.14.414.33.3%01
3.6.1413.52.6%01
3.6.1134.81.5%00
3.6.1015.01.5%00
3.6.117.51.1%01
3.617.51.1%01
3.5.527.23.1%02
3.5.427.23.1%02
3.5.327.23.1%02
3.5.227.23.1%02
3.5.137.02.7%03
3.5.047.02.7%04
3.1.437.02.6%03
3.1.337.02.6%03
3.1.237.02.6%03
3.1.037.02.6%03