Description
|
|
A vulnerability has been identified in eFront, which could be exploited by attackers to gain knowledge of sensitive information. This issue is caused by an input validation error in the "www/editor/tiny_mce/langs/language.php" script when processing the "langname" parameter, which could be exploited by attackers to include or disclose the contents of local files with the privileges of the web server.
Note: The application does not properly validate extensions of uploaded files, which could allow attackers to upload malicious PHP scripts via "www/forum/new_message.php".
|