PT-2026-2178 · Unknown · Open Eclass

Ashifcoder

·

Publicado

2026-01-08

·

Atualizado

2026-01-22

·

CVE-2026-22241

CVSS v4.0

8.6

Alta

VetorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. Prior to version 4.2, a flaw exists in the theme import functionality that allows an attacker with administrative privileges to upload arbitrary files to the server's file system. This is due to a lack of validation or sanitization of files within uploaded zip archives, potentially leading to remote code execution on the web server.
Recommendations Versions prior to 4.2 should be updated to version 4.2 or later.

Exploit

Correção

RCE

Unrestricted File Upload

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-22241
GHSA-GQ72-7MWG-424R
GHSA-RF6J-XGQP-WJXG

Produtos afetados

Open Eclass