CVE-2020-37112: GUnet OpenEclass 1.7.3 E-learning platform - 'month' SQL Injection
GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unvalidated parameters. Attackers can exploit the 'month' parameter in the agenda module and other endpoints to extract sensitive database information using error-based or time-based injection techniques.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37112?
CVE-2020-37112 has been classified as a critical security vulnerability due to its ability to allow authenticated attackers to execute malicious SQL queries.
How do I fix CVE-2020-37112?
To fix CVE-2020-37112, you should update GUnet OpenEclass to the latest version where the SQL injection vulnerabilities have been addressed.
What components are affected by CVE-2020-37112?
CVE-2020-37112 affects the agenda module of GUnet OpenEclass 1.7.3.
What are the potential impacts of CVE-2020-37112?
Exploitation of CVE-2020-37112 could allow attackers to manipulate database queries, leading to data leakage, modification, or deletion.
Who is at risk from CVE-2020-37112?
Authenticated users of GUnet OpenEclass 1.7.3 are at risk of exploitation due to the SQL injection vulnerabilities.