GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure
Vulnerability Description
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access controls and information disclosure flaws in various modules. Attackers can retrieve system info, version info, and view or download other users' files without proper authorization.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-37114
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- emaragkos
References
More from Openeclass
View All →Affected Vendor
Openeclass
View all reports →