CVE-2024-38530

Source
https://cve.org/CVERecord?id=CVE-2024-38530
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38530.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-38530
Aliases
  • GHSA-88c3-hp7p-grgg
Published
2024-08-12T14:50:32.285Z
Modified
2026-02-17T00:35:00.556768Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"
Details

The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.

Database specific
{
    "cwe_ids": [
        "CWE-434"
    ],
    "cna_assigner": "GitHub_M",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/38xxx/CVE-2024-38530.json"
}
References

Affected packages

Git / github.com/gunet/openeclass

Affected ranges

Type
GIT
Repo
https://github.com/gunet/openeclass
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

Release_3.*
Release_3.0
Release_3.1
Release_3.1.1
Release_3.1.2
Release_3.10
Release_3.10.1
Release_3.10.2
Release_3.11
Release_3.11.1
Release_3.11.2
Release_3.12
Release_3.12.1
Release_3.12.2
Release_3.12.3
Release_3.12.4
Release_3.13
Release_3.13.1
Release_3.13.2
Release_3.14
Release_3.14.1
Release_3.15
Release_3.2
Release_3.2.1
Release_3.2.2
Release_3.2.3
Release_3.3
Release_3.3.1
Release_3.3.2
Release_3.4
Release_3.4.1
Release_3.4.2
Release_3.4.3
Release_3.4.4
Release_3.6.1
Release_3.6.2
Release_3.6.3
Release_3.6.4
Release_3.7
Release_3.7.1
Release_3.7.2
Release_3.8
Release_3.8.1
Release_3.8.2
Release_3.8.3
Release_3.8.4
Release_3.9
Release_3.9.1
Release_3.9.2

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-38530.json"