PT-2026-5861 · Openclass+1 · Gunet Open Eclass+1

Emaragkos

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2020-37116

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions GUnet OpenEclass version 1.7.3
Description The software includes phpMyAdmin 2.10.0.2 by default, which permits remote logins. Attackers with platform access can remotely access phpMyAdmin and upload a shell to view the config.php file. This allows the retrieval of the MySQL password, potentially leading to a full database compromise.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2020-37116

Affected Products

Gunet Open Eclass
Open Eclass Platform