CVE-2026-24671
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated high-privileged users (teachers or administrators) to inject malicious JavaScript into multiple user-controllable input fields across the application, which is executed when other users access affected pages. This issue has been patched in version 4.2.
Vendor
Product
CWE
Yayın Tarihi
2026-02-03 18:16:23
Güncelleme
2026-02-10 18:21:25
Source Identifier
security-advisories@github.com
KEV Date Added
-