CVE-2020-24381

HIGH

GUnet Open eClass Platform <3.11 - Info Disclosure

Title source: llm
STIX 2.1

Description

GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.

References (2)

Core 2
Core References
Third Party Advisory x_refsource_misc
https://emaragkos.gr/cve-2020-24381/
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://github.com/gunet/openeclass/issues/39

Scores

CVSS v3 7.5
EPSS 0.0136
EPSS Percentile 68.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
gunet/open_eclass_platform < 3.11
Published Aug 19, 2020
Tracked Since Feb 18, 2026