Записи Openeclass
8 опубликованных записей вендора openeclass.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 3
- С записью об исправлении
- 12,5 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-434 Unrestricted Upload of File with Dangerous Type4
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
8 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2024-31777Proof of concept | File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.popeneclass · openeclass · CWE-434 | Критическая9,8 | — | 3,8 % | 13 июн. 2024 г. |
39Наблюдать | CVE-2024-38530Эксплойта нет | Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"openeclass · openeclass · CWE-434 | Критическая9,8 | — | 0,8 % | 12 авг. 2024 г. |
36Наблюдать | CVE-2024-26503Proof of concept | Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code vopeneclass · openeclass · CWE-434 | Критическая9,1 | — | 1,1 % | 14 мар. 2024 г. |
30Наблюдать | CVE-2026-22241Proof of concept | Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)openeclass · openeclass · CWE-434 | Высокая7,3 | — | 3,3 % | 8 янв. 2026 г. |
27Наблюдать | CVE-2022-33116Эксплойта нет | An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attackopeneclass · openeclass · CWE-22 | Средняя6,5 | — | 1,8 % | 27 июн. 2022 г. |
24Наблюдать | CVE-2017-7389Эксплойта нет | Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'.openeclass · openeclass · CWE-79 | Средняя6,1 | — | 0,8 % | 31 мар. 2017 г. |
21Наблюдать | CVE-2024-33253Эксплойта нет | Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged aopeneclass · openeclass · CWE-79 | Средняя5,4 | — | 0,4 % | 13 июн. 2024 г. |
21Наблюдать | CVE-2025-65734Эксплойта нет | An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, openeclass · openeclass · CWE-79 | Средняя5,4 | — | 0,2 % | 16 мар. 2026 г. |
- CVE-2024-3177740В плане
File Upload vulnerability in openeclass v.3.15 and before allows an attacker to execute arbitrary code via a crafted file to the certbadge.p
КритическаяCVSS 9,8Proof of conceptEPSS 4 %openeclass · openeclass13 июн. 2024 г.
- CVE-2024-3853039Наблюдать
Open eClass Platform allows Arbitrary File Upload in "modules/h5p/save.php"
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %openeclass · openeclass12 авг. 2024 г.
- CVE-2024-2650336Наблюдать
Unrestricted File Upload vulnerability in Greek Universities Network Open eClass v.3.15 and earlier allows attackers to run arbitrary code v
КритическаяCVSS 9,1Proof of conceptEPSS 1 %openeclass · openeclass14 мар. 2024 г.
- CVE-2026-2224130Наблюдать
Open eClass has Unrestricted File Upload that Leads to Remote Code Execution (RCE)
ВысокаяCVSS 7,3Proof of conceptEPSS 3 %openeclass · openeclass8 янв. 2026 г.
- CVE-2022-3311627Наблюдать
An issue in the jmpath variable in /modules/mindmap/index.php of GUnet Open eClass Platform (aka openeclass) v3.12.4 and below allows attack
СредняяCVSS 6,5Эксплойта нетEPSS 2 %openeclass · openeclass27 июн. 2022 г.
- CVE-2017-738924Наблюдать
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'.
СредняяCVSS 6,1Эксплойта нетEPSS 1 %openeclass · openeclass31 мар. 2017 г.
- CVE-2024-3325321Наблюдать
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged a
СредняяCVSS 5,4Эксплойта нетEPSS 0 %openeclass · openeclass13 июн. 2024 г.
- CVE-2025-6573421Наблюдать
An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13,
СредняяCVSS 5,4Эксплойта нетEPSS 0 %openeclass · openeclass16 мар. 2026 г.