CVE-2019-25320: Amitkolloldey Elearning-Script
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
E Learning Script 1.0 contains an authentication bypass vulnerability that allows attackers to access the dashboard without valid credentials by manipulating login parameters. Attackers can exploit the /login.php file by sending a specific payload '=''or' to bypass authentication and gain unauthorized access to the system.
Affected products
- Amitkolloldey Elearning-Script: version 1.0 only
Published 2026-02-12. Last modified 2026-06-17.