CVE-2020-24381
Summary
| CVE | CVE-2020-24381 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-08-19 12:15:00 UTC |
| Updated | 2022-04-30 02:34:00 UTC |
| Description | GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default. |
Risk And Classification
Problem Types: CWE-200
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Gunet | Open Eclass Platform | All | All | All | All |
| Application | Gunet | Open Eclass Platform | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| GUnet Open eClass CVE-2020-24381 - emaragkos Blog | MISC | emaragkos.gr | Third Party Advisory |
| Improper Access Control by Directory Listing Misconfiguration · Issue #39 · gunet/openeclass · GitHub | CONFIRM | github.com | Exploit, Issue Tracking, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.