PT-2022-21697 · Gunet · Gunet Open Eclass Platform
Published
2022-06-27
·
Updated
2022-07-07
·
CVE-2022-33116
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GUnet Open eClass Platform versions 3.12.4 and below
Description
An issue in the
jmpath variable in the "/modules/mindmap/index.php" endpoint of GUnet Open eClass Platform allows attackers to read arbitrary files via a directory traversal.Recommendations
For versions 3.12.4 and below, consider restricting access to the "/modules/mindmap/index.php" endpoint until a patch is available. As a temporary workaround, avoid using the
jmpath variable in the affected endpoint to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gunet Open Eclass Platform