CVE-2020-37114: GUnet OpenEclass 1.7.3 E-learning platform - Information Disclosure
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access controls and information disclosure flaws in various modules. Attackers can retrieve system info, version info, and view or download other users' files without proper authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37114?
The severity of CVE-2020-37114 is considered to be medium due to its impact on information disclosure.
How does CVE-2020-37114 affect users?
CVE-2020-37114 allows both unauthenticated and authenticated users to access sensitive information, potentially compromising user privacy.
How do I fix CVE-2020-37114?
To fix CVE-2020-37114, ensure that proper access controls are implemented to restrict information disclosure.
What types of information can be disclosed due to CVE-2020-37114?
CVE-2020-37114 can disclose sensitive information such as system information, application version details, and uploaded assessments from other students.
Is the CVE-2020-37114 vulnerability widespread?
CVE-2020-37114 specifically affects version 1.7.3 of the GUnet OpenEclass e-learning platform.