ZeroHour

CVE-2026-24669

PoC
CVSS 3.1
7.8 high
EPSS
<1%p5
Published
()
Modified
Description

The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, an insecure password reset mechanism allows local attackers to reuse a valid password reset token after it has already been used, enabling unauthorized password changes and potential account takeover. This issue has been patched in version 4.2.

Vendors
gunet
Products
open eclass platform
Weakness
CWE-613
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.