CVE-2022-33116: Path Traversal
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-33116?
CVE-2022-33116 has been rated as a high severity vulnerability due to its potential for directory traversal attacks that allow unauthorized file access.
How do I fix CVE-2022-33116?
To fix CVE-2022-33116, update the GUnet Open eClass Platform to version 3.12.5 or later, where the vulnerability has been patched.
What systems are affected by CVE-2022-33116?
CVE-2022-33116 affects GUnet Open eClass Platform versions 3.12.4 and below.
What type of attack does CVE-2022-33116 enable?
CVE-2022-33116 enables attackers to execute directory traversal attacks, allowing them to read arbitrary files on the server.
What component of GUnet Open eClass Platform is vulnerable in CVE-2022-33116?
The vulnerability in CVE-2022-33116 is found in the jmpath variable within the mindmap module located in index.php.