CVE Vulnerabilities

CVE-2020-37115

Plaintext Storage of a Password

Published: Feb 03, 2026 | Modified: Feb 10, 2026
CVSS 3.x
4.9
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

GUnet OpenEclass 1.7.3 stores user credentials in plaintext, allowing administrators to view all registered users usernames and passwords without encryption. This vulnerability exposes sensitive information and increases the risk of credential theft and unauthorized access.

Weakness

The product stores a password in plaintext within resources such as memory or files.

Affected Software

NameVendorStart VersionEnd Version
Open_eclass_platformGunet1.7.3 (including)1.7.3 (including)

Potential Mitigations

References