Changelogpatch
https://download.openeclass.org/files/docs/1.7/CHANGES.txt CVE-2020-37112
HIGH
GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
Record summary
CVE-2020-37112 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.
Description
GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unvalidated parameters. Attackers can exploit the 'month' parameter in the agenda module and other endpoints to extract sensitive database information using error-based or time-based injection techniques.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GUnet OpenEclassBrowse Openeclass / GUnet OpenEclass | CVE List | 1.7.3 | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionExploitDB exploitby emaragkosNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37112 ExploitDB-48163exploit
https://www.exploit-db.com/exploits/48163 Official Vendor Homepageproduct
https://www.openeclass.org/ VulnCheck Advisory: GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionThird-party advisory
https://www.vulncheck.com/advisories/gunet-openeclass-e-learning-platform-month-sql-injection