Vulnerability Description
An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resulting in data compromise. An attacker can use a browser to trigger these vulnerabilities, and no special tools are required.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Epignosishq | Efront Lms | <= 5.2.12 |
Related Weaknesses (CWE)
References
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0859ExploitThird Party Advisory
- https://talosintelligence.com/vulnerability_reports/TALOS-2019-0859ExploitThird Party Advisory
FAQ
What is CVE-2019-5070?
CVE-2019-5070 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An exploitable SQL injection vulnerability exists in the unauthenticated portion of eFront LMS, versions v5.2.12 and earlier. Specially crafted web request to login page can cause SQL injections, resu...
How severe is CVE-2019-5070?
CVE-2019-5070 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-5070?
Check the references section above for vendor advisories and patch information. Affected products include: Epignosishq Efront Lms.