Open Eclass Platform

Vendor:

First CVE: Aug 19, 2020 · Active for 5 years

20
Total CVEs
More Total CVEs than 94% of tracked products
6.7
Avg CVEs / Year
Higher CVE frequency than 92% of tracked products
6.3
Avg CVSS
Higher Avg CVSS than 26% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Open Eclass Platform over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 19, 2020
5 years ago
Most Recent CVE
Feb 3, 2026
171 days ago

CVE Severity & Scoring

Open Eclass Platform20 CVEs
All CVEs352,231 CVEs
MediumHigh
Attack Vector
Local1 (5.0%)
Network19 (95.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (95.0%)
High1 (5.0%)
Unknown0 (0.0%)
User Interaction
None13 (65.0%)
Unknown0 (0.0%)
Required7 (35.0%)
Privileges Required
Low10 (50.0%)
High2 (10.0%)
None8 (40.0%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (20 CVEs).

20 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web
Feb 3, 20268.827NONO
GUnet OpenEclass 1.7.3 includes phpMyAdmin 2.10.0.2 by default, which allows remote logins. Attackers with access to the platform can remotely access phpMyAdmin and, after uploadin
Feb 3, 20268.825NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers
Feb 3, 20267.823NONO
GUnet Open eClass (aka openeclass) before 3.12.2 allows XSS via the modules/auth/formuser.php auth parameter.
Jun 11, 20226.123NONO
GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks d
Aug 19, 20207.523NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability all
Feb 3, 20267.522NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s
Feb 3, 20266.520NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated s
Feb 3, 20266.520NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multipl
Feb 3, 20266.520NONO
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows aut
Feb 3, 20265.420NONO

Exploit Exposure

Signals from CVEs in this product scope (20 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (20 CVEs).

Media Mentions

Signals from CVEs in this product scope (20 CVEs).

Top CNAs Publishing CVEs For Open Eclass Platform

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.7.357.10.4%00