ZeroHour

CVE-2026-24667

CVSS 3.1
5.0 medium
EPSS
<1%p3
Published
()
Modified
Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, failure to invalidate active user sessions after a password change allows existing session tokens to remain valid, potentially enabling unauthorized continued access to user accounts. This issue has been patched in version 4.2.

Vendors
gunet
Products
open eclass platform
Weakness
CWE-613
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.