PT-2022-21697 · Gunet · Gunet Open Eclass Platform

Published

2022-06-27

·

Updated

2022-07-07

·

CVE-2022-33116

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GUnet Open eClass Platform versions 3.12.4 and below
Description An issue in the jmpath variable in the "/modules/mindmap/index.php" endpoint of GUnet Open eClass Platform allows attackers to read arbitrary files via a directory traversal.
Recommendations For versions 3.12.4 and below, consider restricting access to the "/modules/mindmap/index.php" endpoint until a patch is available. As a temporary workaround, avoid using the jmpath variable in the affected endpoint to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33116

Affected Products

Gunet Open Eclass Platform