CVE-2013-7194

eFront 3.6.14 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) Last name, (2) Lesson name, or (3) Course name field.

Exploits (1)

exploitdb WORKING POC VERIFIED
by sajith · textwebappsphp
https://www.exploit-db.com/exploits/30213

Scores

EPSS 0.0040
EPSS Percentile 60.3%

Details

CWE
CWE-79
Status published
Products (2)
efrontlearning/efront
n/a/n/a
Published Dec 21, 2013
Tracked Since Feb 18, 2026