PT-2026-2178 · Unknown · Open Eclass

Ashifcoder

·

Published

2026-01-08

·

Updated

2026-01-22

·

CVE-2026-22241

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. Prior to version 4.2, a flaw exists in the theme import functionality that allows an attacker with administrative privileges to upload arbitrary files to the server's file system. This is due to a lack of validation or sanitization of files within uploaded zip archives, potentially leading to remote code execution on the web server.
Recommendations Versions prior to 4.2 should be updated to version 4.2 or later.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-22241
GHSA-GQ72-7MWG-424R
GHSA-RF6J-XGQP-WJXG

Affected Products

Open Eclass