CVE-2025-65734

An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file.
Configurations

Configuration 1 (hide)

cpe:2.3:a:openeclass:openeclass:*:*:*:*:*:*:*:*

History

17 Apr 2026, 21:01

Type Values Removed Values Added
CPE cpe:2.3:a:openeclass:openeclass:*:*:*:*:*:*:*:*
First Time Openeclass
Openeclass openeclass
References () https://github.com/apostolides - () https://github.com/apostolides - Not Applicable
References () https://huntr.com/bounties/540f743c-fa3e-4be6-9f85-439fff2fc5fe - () https://huntr.com/bounties/540f743c-fa3e-4be6-9f85-439fff2fc5fe - Exploit, Third Party Advisory
References () https://huntr.com/users/apostolides - () https://huntr.com/users/apostolides - Third Party Advisory
References () https://www.linkedin.com/in/thanos-apostolidis-3255591b1/ - () https://www.linkedin.com/in/thanos-apostolidis-3255591b1/ - Not Applicable
Summary
  • (es) Una vulnerabilidad de carga arbitraria de archivos autenticada en el módulo de Cursos/Asignaciones de Trabajo de gunet Open eClass v3.11, y corregida en la v3.13, permite a los atacantes ejecutar código arbitrario mediante la carga de un archivo SVG manipulado.

16 Mar 2026, 18:16

Type Values Removed Values Added
CWE CWE-79
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

16 Mar 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-16 17:16

Updated : 2026-04-17 21:01


NVD link : CVE-2025-65734

Mitre link : CVE-2025-65734

CVE.ORG link : CVE-2025-65734


JSON object : View

Products Affected

openeclass

  • openeclass
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')