CVE-2024-38530 : GUNET OPENECLASS UP TO 3.15 H5P MODULE UNRESTRICTED UPLOAD

Description

The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the “save” functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server’s filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.

References

https://github.com/gunet/openeclass/security/advisories/GHSA-88c3-hp7p-grgg

https://github.com/gunet/openeclass/commit/4449cf8bed40fd8fc4b267a5726fab9f9fe5a191

For More Information

CVERecord

Common Vulnerabilityies and Exposures

Contact us to get started

CVE-2024-8887 : CIRCUTOR Q-SMT 1.0.4 IMPROPER VALIDATION OF SPECIFIED QUANTITY IN INPUT

CVE-2024-8887 : CIRCUTOR Q-SMT 1.0.4 IMPROPER VALIDATION OF SPECIFIED QUANTITY IN INPUT

Description CIRCUTOR Q-SMT in its firmware version 1.0.4, could be affected by a denial of service (DoS) attack if an

CVE-2024-8762 : CODE-PROJECTS CRUD OPERATION SYSTEM 1.0 /UPDATEDATA.PHP SID SQL INJECTION

CVE-2024-8762 : CODE-PROJECTS CRUD OPERATION SYSTEM 1.0 /UPDATEDATA.PHP SID SQL INJECTION

Description A vulnerability was found in code-projects Crud Operation System 1.0. It has been classified as critical. This affects an

CVE-2024-34334 : ORDAT FOSS-ONLINE UP TO 2.24.00 FORGOT PASSWORD SQL INJECTION

CVE-2024-34334 : ORDAT FOSS-ONLINE UP TO 2.24.00 FORGOT PASSWORD SQL INJECTION

Description ORDAT FOSS-Online before v2.24.01 was discovered to contain a SQL injection vulnerability via the forgot password function. References https://mind-bytes.de/sql-injection-in-foss-online-cve-2024-34334/