« Back to list

Gunet

Gunet Open Eclass Platform: vulnerabilities and CVEs

Gunet Open Eclass Platform has 20 published vulnerabilities, 18 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs20
Last 12 months18
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2026-24774Medium (4.3)0.23%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a business logic vulnerability allows authenticated students to improperly mark themselves as…
CVE-2026-24773High (7.5)0.41%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows unauthenticated remote attackers to…
CVE-2026-24674Medium (6.1)0.21%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Reflected Cross-Site Scripting (XSS) vulnerability allows remote attackers to execute arbitrary…
CVE-2026-24673Medium (5.3)0.28%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited…
CVE-2026-24672Medium (5.4)0.22%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious…
CVE-2026-24671Medium (4.8)0.22%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated high-privileged users…
CVE-2026-24670Medium (6.5)0.24%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to create new course units, an…
CVE-2026-24669High (7.8)0.18%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token…
CVE-2026-24668Medium (6.5)0.24%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to add content to existing…
CVE-2026-24667Medium (5)0.15%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens…
CVE-2026-24666Medium (6.5)0.18%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multiple teacher-restricted endpoints allows…
CVE-2026-24665Medium (5.4)0.22%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious…
CVE-2026-24664Medium (5.3)0.29%—Feb 3, 2026
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a username enumeration vulnerability allows unauthenticated attackers to identify valid user…
CVE-2020-37116High (8.7)0.48%—Feb 3, 2026
GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploading a shell, view the config.php file to…
CVE-2020-37115High (7.1)0.29%—Feb 3, 2026
GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users' usernames and passwords without encryption. This vulnerability exposes sensitive information and…
CVE-2020-37114Medium (5.3)0.38%—Feb 3, 2026
GUnet OpenEclass 1.7.3 allows unauthenticated and authenticated users to access sensitive information, including system information, application version, and other students' uploaded assessments, due to improper access…
CVE-2020-37113High (8.7)0.91%—Feb 3, 2026
GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the…
CVE-2020-37112High (7.1)0.32%—Feb 3, 2026
GUnet OpenEclass 1.7.3 contains multiple SQL injection vulnerabilities that allow authenticated attackers to manipulate database queries through unvalidated parameters. Attackers can exploit the 'month' parameter in the…
CVE-2021-44266Medium (6.1)1.0%—Jun 11, 2022
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
CVE-2020-24381High (7.5)1.4%—Aug 19, 2020
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1210 Exploitation of Remote Services4
  2. T1005 Data from Local System2
  3. T1078.001 Default Accounts1
  4. T1190 Exploit Public-Facing Application1
  5. T1203 Exploitation for Client Execution1
  6. T1505.003 Web Shell1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Gunet