Skip to main content

Vendor/product archive

eclass / eclass_ip CVEs

Beta · best-effort

3 CVEs tagged to eclass / eclass_ip2 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2019-9885

Published Jul 25, 2019

eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9884

Published Jul 25, 2019

eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-9886

Published Jul 11, 2019

Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1