CVE-2020-24381: Infoleak
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-24381?
CVE-2020-24381 is a vulnerability in GUnet Open eClass Platform (aka openeclass) before version 3.11 that allows remote attackers to read students' submitted assessments.
What is the severity of CVE-2020-24381?
CVE-2020-24381 has a severity rating of 7.5 (High).
How does CVE-2020-24381 work?
CVE-2020-24381 works by allowing remote attackers to bypass directory listing restrictions and access students' submitted assessments.
How can I fix CVE-2020-24381?
To fix CVE-2020-24381, update GUnet Open eClass Platform to version 3.11 or later, which ensures that the web server blocks directory listings.
Is there any additional information available about CVE-2020-24381?
Yes, you can find additional information about CVE-2020-24381 on the following references: [https://emaragkos.gr/cve-2020-24381/](https://emaragkos.gr/cve-2020-24381/) and [https://github.com/gunet/openeclass/issues/39](https://github.com/gunet/openeclass/issues/39).