📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 6h Global supply_chain Software Development and Technology HIGH 11h Global apt Government/Critical Infrastructure CRITICAL 12h Global vulnerability Enterprise Software / Data Analytics CRITICAL 13h Global vulnerability Artificial Intelligence and Technology HIGH 16h Global general Technology and Artificial Intelligence MEDIUM 20h Global general Technology and Artificial Intelligence HIGH 21h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2020-37113

High ⚡ Exploit Available
GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute ar
CWE-434 — Weakness Type
Published: Feb 3, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.8
🔗 NVD Official
📄 Description (English)

GUnet OpenEclass 1.7.3 allows authenticated users to bypass file extension restrictions when uploading files. By renaming a PHP file to .php3 or .PhP, an attacker can upload a web shell and execute arbitrary code on the server. This vulnerability enables remote code execution by bypassing the intended file type checks in the exercise submission feature.

🤖 AI Executive Summary

CVE-2020-37113 is a critical file upload vulnerability in GUnet OpenEclass 1.7.3 that allows authenticated users to bypass file extension restrictions and upload PHP web shells by using alternate extensions (.php3, .PhP). This enables remote code execution on affected servers. The vulnerability poses significant risk to educational institutions and organizations using this learning management system, particularly given the availability of working exploits.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 22, 2026 01:57
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability directly impacts Saudi educational institutions using OpenEclass, including universities under MOHE oversight and private educational platforms. Secondary impact extends to government agencies using this LMS for training programs. The vulnerability enables insider threats and compromised account scenarios to escalate to full server compromise. Risk is elevated in Saudi context due to potential data exposure of student records and institutional research data, which may trigger PDPL (Personal Data Protection Law) compliance violations. Healthcare institutions using similar LMS platforms for training are also at risk.
🏢 Affected Saudi Sectors
Education (Universities, Colleges, Training Centers) Government (Training and Development Programs) Healthcare (Medical Training Programs) Corporate Training Non-Profit Organizations
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all instances of GUnet OpenEclass 1.7.3 in your environment using network scanning and asset inventory tools
2. Restrict access to the exercise submission feature to trusted users only
3. Implement Web Application Firewall (WAF) rules to block uploads with extensions: .php, .php3, .php4, .php5, .phtml, .PhP, .pHp, etc.
4. Monitor web server logs for suspicious file uploads and execution attempts

PATCHING:
5. Upgrade immediately to GUnet OpenEclass 1.7.4 or later version that implements proper file type validation
6. Verify patch deployment across all instances before re-enabling file upload features

COMPENSATING CONTROLS (if immediate patching not possible):
7. Disable PHP execution in upload directories via web server configuration (.htaccess or nginx config)
8. Implement strict file type validation on both client and server side using MIME type checking and magic bytes verification
9. Store uploaded files outside web root directory
10. Rename uploaded files to remove original extensions

DETECTION:
11. Deploy IDS/IPS signatures to detect .php3, .phtml, .PhP file uploads
12. Monitor for POST requests to exercise submission endpoints with suspicious file extensions
13. Alert on any PHP execution from upload directories
14. Review access logs for authenticated users uploading files with double extensions or case-variation extensions
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع نسخ GUnet OpenEclass 1.7.3 في بيئتك باستخدام أدوات المسح والجرد
2. تقييد الوصول إلى ميزة تقديم التمارين للمستخدمين الموثوقين فقط
3. تطبيق قواعد جدار حماية تطبيقات الويب لحجب التحميلات بامتدادات: .php, .php3, .php4, .php5, .phtml, .PhP, .pHp، وغيرها
4. مراقبة سجلات خادم الويب للتحميلات والمحاولات المريبة

التصحيح:
5. الترقية فوراً إلى GUnet OpenEclass 1.7.4 أو إصدار أحدث يطبق التحقق الصحيح من نوع الملف
6. التحقق من نشر التصحيح عبر جميع النسخ قبل إعادة تفعيل ميزات تحميل الملفات

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكناً):
7. تعطيل تنفيذ PHP في مجلدات التحميل عبر إعدادات خادم الويب
8. تطبيق التحقق الصارم من نوع الملف على جانب العميل والخادم باستخدام التحقق من نوع MIME
9. تخزين الملفات المحملة خارج جذر الويب
10. إعادة تسمية الملفات المحملة لإزالة الامتدادات الأصلية

الكشف:
11. نشر توقيعات IDS/IPS للكشف عن تحميلات .php3 و .phtml و .PhP
12. مراقبة طلبات POST إلى نقاط نهاية تقديم التمارين بامتدادات ملفات مريبة
13. التنبيه على أي تنفيذ PHP من مجلدات التحميل
14. مراجعة سجلات الوصول للمستخدمين المصرحين الذين يحملون ملفات بامتدادات مزدوجة أو متغيرة الحالة
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.14.2.1 - Information security requirements analysis and specification A.14.2.5 - Secure development environment A.12.2.1 - Monitoring and logging A.12.4.1 - Event logging A.5.2.1 - User registration and access rights management
🔵 SAMA CSF
ID.SC-4 - Supply chain processes and practices PR.DS-1 - Data security and privacy PR.IP-1 - Security policy and processes DE.CM-1 - The network is monitored to detect potential cybersecurity events RS.MI-1 - Incidents are contained
🟡 ISO 27001:2022
A.6.1.1 - Information security policies A.8.1.1 - User endpoint devices A.12.4.1 - Event logging A.14.2.1 - Secure development policy A.14.2.5 - Secure development environment
🟣 PCI DSS v4.0.1
6.2 - Ensure all system components and software are protected from known vulnerabilities 6.5.8 - Improper access control 11.3 - Penetration testing
📦 Affected Products / CPE 1 entries
gunet:open_eclass_platform:1.7.3
📊 CVSS Score
8.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.8
CWECWE-434
EPSS0.18%
Exploit ✓ Yes
Patch ✓ Yes
Published 2026-02-03
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
exploit-available CWE-434
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.