CVE-2024-33253: XSS
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title and description fields of the badge template editing function.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-33253?
CVE-2024-33253 is classified as a medium severity vulnerability due to its potential for arbitrary code execution by authenticated privileged attackers.
How do I fix CVE-2024-33253?
To fix CVE-2024-33253, upgrade GUnet OpenEclass E-learning Platform to version 3.16 or later, which addresses the XSS vulnerability.
What software versions are affected by CVE-2024-33253?
CVE-2024-33253 affects GUnet OpenEclass E-learning Platform versions 3.15 and earlier.
Who is impacted by CVE-2024-33253?
Authenticated privileged users of GUnet OpenEclass E-learning Platform can exploit CVE-2024-33253 to execute arbitrary code.
What type of vulnerability is CVE-2024-33253?
CVE-2024-33253 is a Cross-Site Scripting (XSS) vulnerability that allows code execution through the badge template editing function.