PT-2026-6198 · Unknown · Open Eclass

·

CVE-2026-24666

·

Published

2026-02-03

·

Updated

2026-02-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A Cross-Site Request Forgery (CSRF) issue exists in teacher-restricted endpoints prior to version 4.2. This allows attackers to trick authenticated teachers into performing unwanted actions, such as altering assignment grades, through specially designed requests. The affected endpoints allow unauthorized actions.
Recommendations Update to version 4.2 or later.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24666
GHSA-CGMH-73QG-28FM

Affected Products

Open Eclass