The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.
History

Tue, 13 Aug 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Openeclass
Openeclass openeclass
CPEs cpe:2.3:a:openeclass:openeclass:*:*:*:*:*:*:*:*
Vendors & Products Openeclass
Openeclass openeclass

Mon, 12 Aug 2024 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Gunet
Gunet open Eclass Platform
CPEs cpe:2.3:a:gunet:open_eclass_platform:*:*:*:*:*:*:*:*
Vendors & Products Gunet
Gunet open Eclass Platform
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 12 Aug 2024 15:00:00 +0000

Type Values Removed Values Added
Description The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.
Title Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2024-08-12T14:50:32.285Z

Updated: 2024-08-12T15:30:52.981Z

Reserved: 2024-06-18T16:37:02.729Z

Link: CVE-2024-38530

cve-icon Vulnrichment

Updated: 2024-08-12T15:30:47.599Z

cve-icon NVD

Status : Analyzed

Published: 2024-08-12T15:15:20.743

Modified: 2024-08-13T17:17:47.693

Link: CVE-2024-38530

cve-icon Redhat

No data.