CVE-2026-24673: Open eClass Has File Upload Filter Bypass via ZIP Archive Extraction
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding them inside ZIP archives and extracting them using the application’s built-in decompression functionality. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24673?
CVE-2026-24673 is considered a high severity vulnerability due to its potential for file upload exploitations.
How do I fix CVE-2026-24673?
To mitigate CVE-2026-24673, upgrade to Open eClass version 4.2 or later which addresses the file upload validation bypass.
What kind of files can be uploaded due to CVE-2026-24673?
CVE-2026-24673 allows the upload of files with prohibited extensions, potentially leading to malicious file execution.
Who is affected by CVE-2026-24673?
Users of Open eClass versions prior to 4.2 are affected by CVE-2026-24673 due to improper file upload validation.
What is the impact of CVE-2026-24673?
The impact of CVE-2026-24673 includes unauthorized file uploads that may lead to code execution or data breaches.