CVE-2020-37115: GUnet OpenEclass 1.7.3 E-learning platform - Plaintext Password Storage
GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37115?
CVE-2020-37115 is considered a high severity vulnerability due to the plaintext storage of user passwords.
How do I fix CVE-2020-37115?
To fix CVE-2020-37115, update to a later version of GUnet OpenEclass that implements proper password encryption.
What impact does CVE-2020-37115 have on users?
CVE-2020-37115 allows unauthorized access to user credentials, significantly compromising user privacy and security.
Are all versions of GUnet OpenEclass affected by CVE-2020-37115?
Only GUnet OpenEclass version 1.7.3 is listed as affected by CVE-2020-37115.
How can administrators mitigate the risks associated with CVE-2020-37115?
Administrators should immediately change passwords and upgrade the software to a secure version to mitigate risks from CVE-2020-37115.