Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a file upload validation bypass vulnerability allows attackers to upload files with prohibited extensions by embedding them inside ZIP archives and extracting them using the application’s built-in decompression functionality. This issue has been patched in version 4.2.

INFO

Published Date :

2026-02-03T16:56:59.723Z

Last Modified :

2026-02-04T16:52:24.978Z

Source :

GitHub_M
AFFECTED PRODUCTS

The following products are affected by CVE-2026-24673 vulnerability.

Vendors Products
Gunet
  • Open Eclass Platform
Openeclass
  • Openeclass
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2026-24673.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact