CVE-2026-24674: Open eClass is Vulnerable to Reflected Cross-Site Scripting (XSS) in Multiple Endpoints
The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Reflected Cross-Site Scripting (XSS) vulnerability allows remote attackers to execute arbitrary JavaScript in the context of authenticated users by crafting malicious URLs and tricking victims into visiting them. This issue has been patched in version 4.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-24674?
CVE-2026-24674 is classified as a medium severity vulnerability due to its potential for exploitation via reflected XSS.
How does CVE-2026-24674 affect Open eClass?
CVE-2026-24674 allows remote attackers to execute arbitrary scripts on users' browsers through vulnerable endpoints in Open eClass.
What versions of Open eClass are affected by CVE-2026-24674?
CVE-2026-24674 affects all versions of Open eClass prior to version 4.2.
How can I fix CVE-2026-24674?
To fix CVE-2026-24674, upgrade Open eClass to version 4.2 or later to mitigate the reflected XSS vulnerability.
Are there any mitigations for CVE-2026-24674 if I can't upgrade right now?
If an upgrade is not possible, implement input validation and output encoding to reduce the risk of exploitation from CVE-2026-24674.