Record summary

CVE-2020-37112 has a selected CVSS score of 7.1 (high); EIP currently links 1 catalogued exploit.

Description

GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unvalidated parameters. Attackers can exploit the 'month' parameter in the agenda module and other endpoints to extract sensitive database information using error-based or time-based injection techniques.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationPoC
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.7.3affected

Proofs of concept

1

Catalogued exploits

ExploitDBGUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionExploitDB exploitby emaragkosNot analyzed1 file

linked to 5 vulnerabilities

ExploitDB

PoC details

References

5