CVE-2015-4461: Efrontlearning Efront
Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.
Absolute path traversal vulnerability in eFront CMS 3.6.15.4 and earlier allows remote Professor users to obtain sensitive information via a full pathname in the other parameter.
Affected products
- Efrontlearning Efront: up to and including 3.6.15.4
Published 2018-02-05. Last modified 2026-06-17.