CVE-2026-24666

MEDIUM

Open eClass <4.2 - CSRF

Title source: llm

Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multiple teacher-restricted endpoints allows attackers to induce authenticated teachers to perform unintended actions, such as modifying assignment grades, via crafted requests. This issue has been patched in version 4.2.

Scores

CVSS v3 6.5
EPSS 0.0004
EPSS Percentile 10.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N

Classification

CWE
CWE-352
Status published

Affected Products (1)

gunet/open_eclass_platform < 4.2

Timeline

Published Feb 03, 2026
Tracked Since Feb 18, 2026