top of page
perceptive_background_267k.jpg

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vuln…

Published:

2 februari 2026 om 23:00:00

Alert date:

3 februari 2026 om 19:04:17

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications

The Open eClass platform (formerly GUnet eClass) course management system contains a stored Cross-Site Scripting (XSS) vulnerability in versions prior to 4.2. The vulnerability allows authenticated students to inject malicious JavaScript code into uploaded assignment files. When instructors view these submissions, the malicious code executes in their browsers. This stored XSS attack vector could potentially allow students to compromise instructor accounts or steal sensitive information. The vulnerability has been patched in version 4.2 of the Open eClass platform.

Technical details

Mitigation steps:

Affected products:

Open eClass
GUnet eClass

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page