
[CVE-2026-24665: HIGH] Stored XSS vulnerability in Open eClass (formerly GUnet eClass) before v4.2 allows students to inject code in assignment files that executes for instructors. Update to v4.2 for the fix.#cve,CVE-2026-24665,#cybersecurity https://cvefind.com/CVE-2026-24665
Post summary
A high severity stored XSS flaw in Open eClass versions before 4.2 allows students to inject code into assignment files that executes in instructors’ browsers. The issue is fixed in version 4.2; users should update immediately.

