CVE-2019-9886: Eclass IP

High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.

Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.

Affected products

  • Eclass Eclass IP: before 2.5.10.2.1 (fixed in 2.5.10.2.1)

Published 2019-07-11. Last modified 2026-06-17.