PT-2026-6198 · Unknown · Open Eclass

Stolichnayer

·

Publicado

2026-02-03

·

Atualizado

2026-02-10

·

CVE-2026-24666

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A Cross-Site Request Forgery (CSRF) issue exists in teacher-restricted endpoints prior to version 4.2. This allows attackers to trick authenticated teachers into performing unwanted actions, such as altering assignment grades, through specially designed requests. The affected endpoints allow unauthorized actions.
Recommendations Update to version 4.2 or later.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24666
GHSA-CGMH-73QG-28FM

Produtos afetados

Open Eclass