CVE-2026-24773

HIGH

Open eClass Platform < 4.2 - Unauthenticated Insecure Direct Object Reference

Title source: llm
STIX 2.1

Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows unauthenticated remote attackers to access personal files of other users by directly requesting predictable user identifiers. This issue has been patched in version 4.2.

References (1)

Core 1
Core References

Scores

CVSS v3 7.5
EPSS 0.0035
EPSS Percentile 26.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-639
Status published
Products (1)
gunet/open_eclass_platform < 4.2
Published Feb 03, 2026
Tracked Since Feb 18, 2026