Record summary

CVE-2020-37114 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.

Description

GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access controls and information disclosure flaws in various modules. Attackers can retrieve system info, version info, and view or download other users' files without proper authorization.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List1.7.3 (2007)affected

Proofs of concept

1

Catalogued exploits

ExploitDBGUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionExploitDB exploitby emaragkosNot analyzed1 file

linked to 5 vulnerabilities

ExploitDB

PoC details

References

5