CVE-2024-31026 Details
Description
An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.
A vulnerability allowing HTML injection has been identified in GUnet Open eClass Platform versions through 3.15. This issue resides in the chat input field of the course module, where remote attackers can execute arbitrary code.
It is recommended to escape or strip HTML from the chat input or to use a whitelist sanitizer when rendering chat content.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://panagiotiscp.github.io/cve-2024-31026-html-injection/ | [email protected] | ExploitTechnical Description |
Weakness Enumeration
No weakness enumeration is available for this CVE.
Affected Products
| Product | Versions |
|---|---|
| Greek Universities Network Open eClass | <= 3.15 |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 29, 2026 | New CVE Received | [email protected] |
Volerion