PT-2026-6206 · Unknown · Open Eclass

Stolichnayer

·

Published

2026-02-03

·

Updated

2026-02-03

·

CVE-2026-24674

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Open eClass versions prior to 4.2
Description The Open eClass platform, previously known as GUnet eClass, is a course management system. A Reflected Cross-Site Scripting (XSS) issue exists in versions prior to 4.2, potentially allowing remote attackers to execute arbitrary JavaScript within the security context of authenticated users. This is achieved by creating malicious URLs and deceiving users into accessing them.
Recommendations Update to version 4.2 or later.

Exploit

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2026-24674
GHSA-GQVP-W22W-W99R

Affected Products

Open Eclass