PT-2019-17452 · Efront · Efront Lms
Yuri Kramarz
·
Published
2019-09-05
·
Updated
2022-06-27
·
CVE-2019-5070
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
eFront LMS versions v5.2.12 and earlier
Description
An exploitable SQL injection issue exists in the unauthenticated portion of the software. A specially crafted web request to the "login page" can cause SQL injections, resulting in data compromise. An attacker can trigger this issue using a browser, with no special tools required.
Recommendations
For versions v5.2.12 and earlier, update to a version later than v5.2.12 to resolve the issue. As a temporary workaround, consider restricting access to the login page to minimize the risk of exploitation.
Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Efront Lms