PT-2026-6196 · Unknown · Open Eclass

Stolichnayer

·

Published

2026-02-03

·

Updated

2026-02-10

·

CVE-2026-24664

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system susceptible to a username enumeration issue. An unauthenticated attacker can determine valid user accounts by observing variations in the login response. The /login endpoint is affected, allowing attackers to test different usernames (username) and analyze the system's response to identify active accounts.
Recommendations Update to version 4.2 or later.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-24664
GHSA-C3WQ-M629-5H2J

Affected Products

Open Eclass