GUnet OpenEclass Information Disclosure Vulnerability

Vulnerability

A vulnerability in GUnet OpenEclass version 1.7.3 allows both unauthenticated and authenticated users to access sensitive information. This includes system details, application version, and other students' uploaded assessments. The issue arises from improper access controls and information disclosure flaws in various modules, enabling unauthorized retrieval of system info, version info, and files from other users.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive information, including personal assessments of other students and potentially exploitable system information.

Reproduction

The vulnerability can be reproduced by accessing specific modules within the OpenEclass platform. Unauthenticated users can retrieve system and version information from designated admin modules. Authenticated students can access other students' assessments by navigating to the 'work' directory of the relevant course.

Added: Feb 3, 2026, 7:51 PM
Updated: Feb 3, 2026, 7:51 PM

Vulnerability Rating

Custom Algorithm
spread
2.2
impact
2.5
exploitability
6.8
remediation
0.0
relevance
2.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.