CVE-2025-65734: XSS
Published Mar 16, 2026
·Updated
An authenticated arbitrary file upload vulnerability in the Courses/Work Assignments module of gunet Open eClass v3.11, and fixed in v3.13, allows attackers to execute arbitrary code via uploading a crafted SVG file.
Affected Software
2 affected components
GUnet Open eClass>3.11<=3.13
OpenEclass OpenEclass>=3.11<3.13
Event History
Mar 16, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-65734?
CVE-2025-65734 is classified as a critical vulnerability due to its potential for attackers to execute arbitrary code.
2
How do I fix CVE-2025-65734?
To fix CVE-2025-65734, upgrade Open eClass from version 3.11 to version 3.13 or later.
3
What types of files are vulnerable in CVE-2025-65734?
CVE-2025-65734 specifically allows the upload of crafted SVG files which can be exploited.
4
Who is affected by CVE-2025-65734?
Users of gunet Open eClass versions 3.11 through 3.12 are at risk of CVE-2025-65734.
5
What can attackers achieve with CVE-2025-65734?
Attackers can execute arbitrary code on the server by exploiting the authenticated arbitrary file upload vulnerability in CVE-2025-65734.