Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openeclass openeclass vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2017-7389
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attack...
Openeclass Openeclass
312
VMScore
CVE-2022-33116
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows malicious users to read arbitrary files via a directory traversal.
Openeclass Openeclass
NA
CVE-2024-31777
GUnet OpenEclass E-learning platform version 3.15 suffers from an unrestricted file upload vulnerability in certbadge.php that allows for remote command execution.
1 Github repository
383
VMScore
CVE-2021-44266
GUnet Open eClass (aka openeclass) prior to 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
Gunet Open Eclass Platform
383
VMScore
CVE-2020-24381
GUnet Open eClass Platform (aka openeclass) prior to 3.11 might allow remote malicious users to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
Gunet Open Eclass Platform
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
authentication bypass
CVE-2024-30043
camera
CVE-2023-40404
CVE-2024-2793
client side
CVE-2024-4469
CVE-2024-3565
CVE-2024-29825
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started