CVE-2020-24381

Source
https://nvd.nist.gov/vuln/detail/CVE-2020-24381
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-24381.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2020-24381
Published
2020-08-19T12:15:11Z
Modified
2025-02-14T11:13:35.913684Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N CVSS Calculator
Summary
[none]
Details

GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default.

References

Affected packages

Git / github.com/gunet/openeclass

Affected ranges

Type
GIT
Repo
https://github.com/gunet/openeclass
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Release_3.*

Release_3.0
Release_3.1
Release_3.1.1
Release_3.1.2
Release_3.10
Release_3.10.1
Release_3.10.2
Release_3.2
Release_3.2.1
Release_3.2.2
Release_3.2.3
Release_3.3
Release_3.3.1
Release_3.3.2
Release_3.4
Release_3.4.1
Release_3.4.2
Release_3.4.3
Release_3.4.4
Release_3.6.1
Release_3.6.2
Release_3.6.3
Release_3.6.4
Release_3.7
Release_3.7.1
Release_3.7.2
Release_3.8
Release_3.8.1
Release_3.8.2
Release_3.8.3
Release_3.8.4
Release_3.9
Release_3.9.1
Release_3.9.2