PT-2024-28056 · Unknown+1 · Open Eclass+1

John-Weasel-4345

·

Published

2024-08-12

·

Updated

2024-08-17

·

CVE-2024-38530

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 3.16
Description The Open eClass platform, a complete Course Management System, contains an arbitrary file upload vulnerability in the "save" functionality of the H5P module. This vulnerability enables unauthenticated users to upload arbitrary files on the server's filesystem, potentially leading to unrestricted remote code execution (RCE) on the backend server, as the upload location is accessible from the internet.
Recommendations For versions prior to 3.16, update to version 3.16 to fix the arbitrary file upload vulnerability in the H5P module. As a temporary workaround, consider restricting access to the H5P module's "save" functionality to prevent unauthenticated file uploads until the update is applied.

Exploit

Fix

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2024-38530
GHSA-88C3-HP7P-GRGG

Affected Products

H5P
Open Eclass