Changelogproduct
https://download.openeclass.org/files/docs/1.7/CHANGES.txt CVE-2020-37114
MEDIUM
GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure
Record summary
CVE-2020-37114 has a selected CVSS score of 5.3 (medium); EIP currently links 1 catalogued exploit.
Description
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access controls and information disclosure flaws in various modules. Attackers can retrieve system info, version info, and view or download other users' files without proper authorization.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 6, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
GUnet OpenEclassBrowse Openeclass / GUnet OpenEclass | CVE List | 1.7.3 (2007) | affected |
Proofs of concept
1Catalogued exploits
ExploitDBGUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL InjectionExploitDB exploitby emaragkosNot analyzed1 file
References
5nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-37114 ExploitDB-48163exploit
https://www.exploit-db.com/exploits/48163 Official Vendor Homepageproduct
https://www.openeclass.org/ VulnCheck Advisory: GUnet OpenEclass 1.7.3 E-learning platform - Information DisclosureThird-party advisory
https://www.vulncheck.com/advisories/gunet-openeclass-e-learning-platform-information-disclosure