From e5b5c41a5e229a855a66821ec4b266c49e38197b Mon Sep 17 00:00:00 2001 From: CVE Team Date: Fri, 10 Sep 2021 04:00:51 +0000 Subject: [PATCH] "-Synchronized-Data." --- 2020/24xxx/CVE-2020-24381.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/2020/24xxx/CVE-2020-24381.json b/2020/24xxx/CVE-2020-24381.json index 043a2cced5b..d865bc574e7 100644 --- a/2020/24xxx/CVE-2020-24381.json +++ b/2020/24xxx/CVE-2020-24381.json @@ -34,7 +34,7 @@ "description_data": [ { "lang": "eng", - "value": "** DISPUTED ** GUnet Open eClass Platform (aka openeclass) through 3.9.2 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings. NOTE: this is disputed because it only affects misconfigured installations." + "value": "GUnet Open eClass Platform (aka openeclass) before 3.11 might allow remote attackers to read students' submitted assessments because it does not ensure that the web server blocks directory listings, and the data directory is inside the web root by default." } ] },