PT-2026-5859 · Openclass+1 · Gunet Open Eclass+1

Emaragkos

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37114

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GUnet OpenEclass version 1.7.3
Description Improper access controls and information disclosure flaws in various modules allow unauthenticated and authenticated users to access sensitive data. This includes system information, application version, and uploaded assessments belonging to other students. Attackers can retrieve system and version details or view and download files from other users without proper authorization.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2020-37114

Affected Products

Gunet Open Eclass
Open Eclass Platform