logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2024-38530

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2024-38530

Description:
The Open eClass platform (formerly known as GUnet eClass) is a complete Course Management System. An arbitrary file upload vulnerability in the "save" functionality of the H5P module enables unauthenticated users to upload arbitrary files on the server's filesystem. This may lead in unrestricted RCE on the backend server, since the upload location is accessible from the internet. This vulnerability is fixed in 3.16.
Last updated date:
08/13/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
08/13/2024
Reference url to background

https://github.com/gunet/openeclass/security/advisories/GHSA-88c3-hp7p-grgg

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2024

Privacy Policy