CVE-2026-24671: Open eClass is Vulnerable to Stored Cross-Site Scripting (XSS) in Multiple High-Privilege User Fields
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Stored Cross-Site Scripting (XSS) vulnerability allows authenticated high-privileged users (teachers or administrators) to inject malicious JavaScript into multiple user-controllable input fields across the application, which is executed when other users access affected pages. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24671?
CVE-2026-24671 is a high severity vulnerability due to its potential for exploitation through stored XSS attacks in high-privilege user fields.
Who is affected by CVE-2026-24671?
Users of Open eClass versions prior to 4.2 are affected by CVE-2026-24671.
How do I fix CVE-2026-24671?
To fix CVE-2026-24671, upgrade Open eClass to version 4.2 or later.
What type of vulnerability is CVE-2026-24671?
CVE-2026-24671 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What are the potential impacts of CVE-2026-24671?
If exploited, CVE-2026-24671 could allow attackers to execute malicious scripts in the context of an authenticated user's session.