PT-2026-6209 · Unknown · Open Eclass

Stolichnayer

·

Publicado

2026-02-03

·

Atualizado

2026-02-10

·

CVE-2026-24773

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A security issue exists where an unauthenticated remote attacker can access personal files belonging to other users. This is possible by directly requesting predictable user identifiers, exploiting an Insecure Direct Object Reference (IDOR). An IDOR occurs when an application uses user-supplied input to directly access objects based on that input. In this case, the application fails to properly validate the user's authorization before granting access to files. The user identifiers are predictable, allowing attackers to enumerate and access files they should not have permission to view.
Recommendations Update to version 4.2 or later.

Exploit

Correção

IDOR

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-24773
GHSA-63PM-PFF4-XC9C

Produtos afetados

Open Eclass