GUnet OpenEclass是希腊GUnet公司的一个学习管理系统。 GUnet OpenEclass 1.7.3版本存在访问控制错误漏洞,该漏洞源于默认包含phpMyAdmin 2.10.0.2,可能导致攻击者获取MySQL密码并完全控制数据库。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Openeclass | GUnet OpenEclass | 1.7.3 (2007) |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Openeclass | GUnet OpenEclass | 1.7.3 (2007) | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2020-37113 | 8.8 HIGH | GUnet OpenEclass 1.7.3 E-learning platform - File Upload Extension Bypass |
| CVE-2020-37112 | 7.1 HIGH | GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection |
| CVE-2020-37115 | 6.5 MEDIUM | GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage |
| CVE-2020-37114 | 4.3 MEDIUM | GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure |
No comments yet