Filtered by vendor Eclass Subscriptions
Filtered by product Eclass Ip Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2019-9884 1 Eclass 1 Eclass Ip 2024-09-17 9.8 Critical
eClass platform < ip.2.5.10.2.1 allows an attacker to use GETS method to request /admin page to bypass the password validation and access management page.
CVE-2019-9885 1 Eclass 1 Eclass Ip 2024-09-17 N/A
eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.
CVE-2019-9886 1 Eclass 1 Eclass Ip 2024-09-16 7.5 High
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.