Ad

CVE-2026-22241

HIGH CVSS 4.0: 7.3 EPSS 0.21%
Updated Jan 23, 2026
Openeclass
Parameter Value
CVSS 7.3 (HIGH)
Affected Versions before 4.1
Fixed In 4.1
Type CWE-434 (Unrestricted File Upload)
Vendor Openeclass
Public PoC No

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an arbitrary file upload vulnerability in the theme import functionality enables an attacker with administrative privileges to upload arbitrary files on the server's file system. The main cause of the issue is that no validation or sanitization of the file's present inside the zip archive.

This leads to remote code execution on the web server. Version 4.2 patches the issue.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Attack Requirements
None
No additional conditions
Privileges Required
High
Admin privileges needed
User Interaction
None
No user interaction needed

Impact Assessment

Confidentiality
High
Complete data leak
Integrity
High
Complete data modification
Availability
High
Complete denial of service

CVSS Vector v4.0

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Openeclass Openeclass
cpe:2.3:a:openeclass:openeclass:*:*:*:*:*:*:*:*
4.1

Related Vulnerabilities