CVE-2019-9885: Eclass IP
Critical severity, CVSS 9.8. EPSS: 2.6% chance of exploitation in the next 30 days.
eClass platform < ip.2.5.10.2.1 allows an attacker to execute SQL command via /admin/academic/studenview_left.php StudentID parameter.
Affected products
- Eclass Eclass IP: before 2.5.10.2.1 (fixed in 2.5.10.2.1)
Published 2019-07-25. Last modified 2026-06-17.