Vulnerabilities (CVE)

Filtered by vendor Epignosishq Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-5069 1 Epignosishq 1 Efront Lms 2022-06-27 6.5 MEDIUM 8.8 HIGH
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
CVE-2020-28597 1 Epignosishq 1 Efront 2022-04-28 5.0 MEDIUM 7.5 HIGH
A predictable seed vulnerability exists in the password reset functionality of Epignosis EfrontPro 5.2.21. By predicting the seed it is possible to generate the correct password reset 1-time token. An attacker can visit the password reset supplying the password reset token to reset the password of an account of their choice.