CVE-2020-37113

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature.
Configurations

Configuration 1 (hide)

cpe:2.3:a:gunet:open_eclass_platform:1.7.3:*:*:*:*:*:*:*

History

17 Jun 2026, 03:17

Type Values Removed Values Added
Summary
  • (es) GUnet OpenEclass 1.7.3 permite a los usuarios autenticados eludir las restricciones de extensión de archivo al subir archivos. Al renombrar un archivo PHP a .php3 o .PhP, un atacante puede subir una web shell y ejecutar código arbitrario en el servidor. Esta vulnerabilidad permite la ejecución remota de código al eludir las comprobaciones de tipo de archivo previstas en la función de envío de ejercicios.

12 Feb 2026, 18:33

Type Values Removed Values Added
First Time Gunet
Gunet open Eclass Platform
CPE cpe:2.3:a:gunet:open_eclass_platform:1.7.3:*:*:*:*:*:*:*
References () https://download.openeclass.org/files/docs/1.7/CHANGES.txt - () https://download.openeclass.org/files/docs/1.7/CHANGES.txt - Release Notes
References () https://www.exploit-db.com/exploits/48163 - () https://www.exploit-db.com/exploits/48163 - Exploit, Third Party Advisory, VDB Entry
References () https://www.openeclass.org/ - () https://www.openeclass.org/ - Product
References () https://www.vulncheck.com/advisories/gunet-openeclass-e-learning-platform-file-upload-extension-bypass - () https://www.vulncheck.com/advisories/gunet-openeclass-e-learning-platform-file-upload-extension-bypass - Third Party Advisory

03 Feb 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-03 18:16

Updated : 2026-06-17 03:17


NVD link : CVE-2020-37113

Mitre link : CVE-2020-37113

CVE.ORG link : CVE-2020-37113


JSON object : View

Products Affected

gunet

  • open_eclass_platform
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type