CVE-2020-37113 describes a critical file upload vulnerability in GUnet OpenEclass 1.7.3, specifically affecting the open_eclass_platform. Authenticated users can bypass file extension restrictions, allowing them to upload malicious PHP files (e.g., by renaming them to .php3 or .PhP) and achieve remote code execution. This vulnerability carries a high CVSS score of 8.8, indicating a low-complexity attack that can lead to complete compromise of confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score of 94/100 suggests a significant potential impact if exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.7.3CPE matchmatch criteria | cpe:2.3:a:gunet:open_eclass_platform:1.7.3:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.