CVE-2015-4462

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
25/07/2017
Last modified:
20/04/2025

Description

Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:efrontlearning:efront:*:*:*:*:*:*:*:* 3.6.15.4 (including)