PT-2026-6198 · Unknown · Open Eclass

Stolichnayer

·

Published

2026-02-03

·

Updated

2026-02-10

·

CVE-2026-24666

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A Cross-Site Request Forgery (CSRF) issue exists in teacher-restricted endpoints prior to version 4.2. This allows attackers to trick authenticated teachers into performing unwanted actions, such as altering assignment grades, through specially designed requests. The affected endpoints allow unauthorized actions.
Recommendations Update to version 4.2 or later.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

CVE-2026-24666
GHSA-CGMH-73QG-28FM

Affected Products

Open Eclass