CVE-2015-4463

Severity CVSS v4.0:
Pending analysis
Type:
CWE-434 Unrestricted Upload of File with Dangerous Type
Publication date:
25/07/2017
Last modified:
20/04/2025

Description

The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:efrontlearning:efront:*:*:*:*:*:*:*:* 3.6.15.4 (including)