PT-2026-6203 · Unknown · Open Eclass

Stolichnayer

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2026-24671

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A Stored Cross-Site Scripting (XSS) issue exists in versions before 4.2, allowing authenticated high-privileged users, such as teachers or administrators, to inject malicious JavaScript into user-controllable input fields. This injected script is then executed when other users access the affected pages.
Recommendations Update to version 4.2 or later.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-24671
GHSA-2X83-4FH2-FCW7

Affected Products

Open Eclass