vendor:
OpenEclass
by:
emaragkos
7.5
CVSS
HIGH
SQL Injection
89
CWE
Product Name: OpenEclass
Affected Version From: 1.7.3
Affected Version To: 1.7.3
Patch Exists: YES
Related CWE: N/A
CPE: a:gunet:openeclass:1.7.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Ubuntu 12
2020
GUnet OpenEclass 1.7.3 E-learning platform – ‘month’ SQL Injection
GUnet OpenEclass 1.7.3 E-learning platform is vulnerable to an unauthenticated information disclosure vulnerability and an authenticated error-based SQL injection vulnerability. The unauthenticated information disclosure vulnerability can be exploited by accessing the system info page at 127.0.0.1/modules/admin/sysinfo, the web-app version info page at 127.0.0.1/README.txt, 127.0.0.1/info/about.php, and 127.0.0.1/upgrade/CHANGES.txt. The authenticated error-based SQL injection vulnerability can be exploited by sending a specially crafted request to the myagenda.php page at 127.0.0.1/modules/agenda/myagenda.php?month=2&year=2020.
Mitigation:
Upgrade to the latest version of GUnet OpenEclass 1.7.3 E-learning platform.