Vulnerabilities > CVE-2019-5069 - Deserialization of Untrusted Data vulnerability in Epignosishq Efront LMS
Attack vector
NETWORK Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
A code execution vulnerability exists in Epignosis eFront LMS v5.2.12. A specially crafted web request can cause unsafe deserialization potentially resulting in PHP code being executed. An attacker can send a crafted web parameter to trigger this vulnerability.
Vulnerable Configurations
Common Weakness Enumeration (CWE)
Talos
id | TALOS-2019-0858 |
last seen | 2019-09-07 |
published | 2019-09-03 |
reporter | Talos Intelligence |
source | http://www.talosintelligence.com/vulnerability_reports/TALOS-2019-0858 |
title | Epignosis eFront LMS PHP deserialization code execution vulnerability |