Description
An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.
Published: 2026-09-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Apply Patch
AI Analysis

Impact

A remote attacker may inject malicious payloads into the chat input field of the Greek Universities Network Open eClass Platform, leading to arbitrary code execution on the server. This flaw violates the integrity and confidentiality of the application and can allow attackers to compromise the entire platform, potentially gaining elevated privileges and access to sensitive data. The flaw is a classic example of code injection, allowing malicious commands to be run within the platform's runtime environment.

Affected Systems

Greek Universities Network (GUnet) Open eClass Platform version 3.15 is affected. The vulnerability resides in the course module's chat feature and is likely present on any deployment of this platform using that version. All institutions hosting the platform without applying a fix are potentially at risk.

Risk and Exploitability

The CVSS score is not publicly provided, but the vulnerability offers remote code execution with minimal user interaction – an attacker only needs to send malicious content via the chat interface. Although EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, the available description indicates a high exploitation potential for any user with access to the chat feature. The absence of a vendor patch at this time raises the risk level, suggesting that attackers could readily exploit the flaw if they can identify a target using the affected platform.

Generated by OpenCVE AI on September 30, 2026 at 04:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the GUnet Open eClass Platform to the latest patched release if it corrects the chat input code execution flaw.
  • If a patch is not available, disable the chat functionality or restrict access to the chat input endpoint to prevent user input from being processed by the server.
  • Apply rigorous input validation and sanitization to the chat inputs, ensuring that any code or scripts are stripped or encoded before execution, in line with CWE‑94 mitigation guidance.

Generated by OpenCVE AI on September 30, 2026 at 04:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description An issue in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the chat input field in the course module.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-29T19:31:04.059Z

Reserved: 2024-03-27T00:00:00.000Z

Link: CVE-2024-31026

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T20:17:07.577

Modified: 2026-09-29T20:17:07.577

Link: CVE-2024-31026

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:30:11Z

Weaknesses

No weakness.