← Back to CVE List

CVE-2015-4462

Published: 2017-07-25T18:29Z
Last Modified: 2024-11-21T02:31Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Absolute path traversal vulnerability in the file_manager component of eFront CMS before 3.6.15.5 allows remote authenticated users to read arbitrary files via a full pathname in the "Upload file from url" field in the file manager for professor.php. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt