Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.
History

Mon, 16 Sep 2024 17:00:00 +0000

Type Values Removed Values Added
Title eClass platform allows user to download arbitrary files without authentication eClass platform allows user to download arbitrary files without authentication

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published: 2019-07-11T18:21:51.743994Z

Updated: 2024-09-16T16:53:38.342Z

Reserved: 2019-03-19T00:00:00

Link: CVE-2019-9886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-07-11T19:15:13.580

Modified: 2020-10-07T14:59:12.617

Link: CVE-2019-9886

cve-icon Redhat

No data.