Vulnerabilities > Openeclass

DATE CVE VULNERABILITY TITLE RISK
2024-08-12 CVE-2024-38530 Unrestricted Upload of File with Dangerous Type vulnerability in Openeclass
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System.
network
low complexity
openeclass CWE-434
critical
9.8
2024-06-13 CVE-2024-33253 Cross-site Scripting vulnerability in Openeclass
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title and description fields of the badge template editing function.
network
low complexity
openeclass CWE-79
5.4
2022-06-27 CVE-2022-33116 Path Traversal vulnerability in Openeclass
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackers to read arbitrary files via a directory traversal.
network
low complexity
openeclass CWE-22
6.5
2017-04-01 CVE-2017-7389 Cross-site Scripting vulnerability in Openeclass
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'.
network
low complexity
openeclass CWE-79
6.1