Vulmon
Recent Vulnerabilities
Product List
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
openeclass openeclass vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2017-7389
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An attack...
Openeclass Openeclass
312
VMScore
CVE-2022-33116
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows malicious users to read arbitrary files via a directory traversal.
Openeclass Openeclass
NA
CVE-2024-31777
File Upload vulnerability in openeclass v.3.15 and before allows an malicious user to execute arbitrary code via a crafted file to the certbadge.php endpoint.
1 Github repository
383
VMScore
CVE-2021-44266
GUnet Open eClass (aka openeclass) prior to 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
Gunet Open Eclass Platform
NA
CVE-2024-33253
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged malicious user to execute arbitrary code via the title and description fields of the badge template editing function.
383
VMScore
CVE-2020-24381
GUnet Open eClass Platform (aka openeclass) prior to 3.11 might allow remote malicious users to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
Gunet Open Eclass Platform
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
CVE-2024-3080
log injection
CVE-2024-6041
CVE-2024-37661
XML external entity
CVE-2024-0845
privilege escalation
CVE-2023-37057
CVE-2024-27801
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started