Gunet

Open Eclass Platform

24 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 29.09.2026 00:00:00
  • Zuletzt bearbeitet 30.09.2026 21:16:52

Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.

  • EPSS 0.21%
  • Veröffentlicht 29.09.2026 00:00:00
  • Zuletzt bearbeitet 01.10.2026 16:17:27

An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.

Exploit
  • EPSS 0.15%
  • Veröffentlicht 03.02.2026 17:00:38
  • Zuletzt bearbeitet 10.02.2026 18:31:05

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already been used, ...

Exploit
  • EPSS 0.21%
  • Veröffentlicht 03.02.2026 16:59:48
  • Zuletzt bearbeitet 10.02.2026 18:32:55

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a broken access control vulnerability allows authenticated students to add content to existing course units, an action normally re...

  • EPSS 0.13%
  • Veröffentlicht 03.02.2026 16:59:32
  • Zuletzt bearbeitet 10.02.2026 18:35:19

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially ena...

Exploit
  • EPSS 0.15%
  • Veröffentlicht 03.02.2026 16:58:57
  • Zuletzt bearbeitet 10.02.2026 18:47:52

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multiple teacher-restricted endpoints allows attackers to induce authenticate...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 03.02.2026 16:58:28
  • Zuletzt bearbeitet 10.02.2026 18:48:23

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a stored Cross-Site Scripting (XSS) vulnerability allows authenticated students to inject malicious JavaScript into uploaded assig...

Exploit
  • EPSS 0.2%
  • Veröffentlicht 03.02.2026 16:58:09
  • Zuletzt bearbeitet 10.02.2026 17:24:23

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a business logic vulnerability allows authenticated students to improperly mark themselves as present in attendance activities, in...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 03.02.2026 16:57:57
  • Zuletzt bearbeitet 10.02.2026 17:25:21

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an Insecure Direct Object Reference (IDOR) vulnerability allows unauthenticated remote attackers to access personal files of other...

Exploit
  • EPSS 0.18%
  • Veröffentlicht 03.02.2026 16:57:07
  • Zuletzt bearbeitet 10.02.2026 17:26:57

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Reflected Cross-Site Scripting (XSS) vulnerability allows remote attackers to execute arbitrary JavaScript in the context of aut...