CVE-2019-9886: Eclass IP
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
Any URLs with download_attachment.php under templates or home folders can allow arbitrary files downloaded without login in BroadLearning eClass before version ip.2.5.10.2.1.
Affected products
- Eclass Eclass IP: before 2.5.10.2.1 (fixed in 2.5.10.2.1)
Published 2019-07-11. Last modified 2026-06-17.