Openeclass Vulnerabilities and Affected Products
Vulnerabilities associated with GUnet OpenEclass.
Products
Clear product- GUnet OpenEclass5 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2020-37116HIGH | GUnet OpenEclass 1.7.3 E-learning platform - phpMyAdmin Remote AccessGUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to obtain the MySQL password, leading to full database compromise. CWE-284Feb 3, 2026 | CVSS8.7v4.0 | EPSS0.415% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37115HIGH | GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password StorageGUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access. CWE-256Feb 3, 2026 | CVSS7.1v4.0 | EPSS0.263% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37114MEDIUM | GUnet OpenEclass 1.7.3 E-learning platform - Information DisclosureGUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access controls and information disclosure flaws in various modules. Attackers can retrieve system info, version info, and view or download other users' files without proper authorization. CWE-200Feb 3, 2026 | CVSS5.3v4.0 | EPSS0.326% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37113HIGH | GUnet OpenEclass 1.7.3 E-learning platform - File Upload Extension BypassGUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature. CWE-434Feb 3, 2026 | CVSS8.7v4.0 | EPSS0.781% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-37112HIGH | GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionGUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unvalidated parameters. Attackers can exploit the 'month' parameter in the agenda module and other endpoints to extract sensitive database information using error-based or time-based injection techniques. CWE-89Feb 3, 2026 | CVSS7.1v4.0 | EPSS0.274% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |