Impact
A remote attacker may inject malicious payloads into the chat input field of the Greek Universities Network Open eClass Platform, leading to arbitrary code execution on the server. This flaw violates the integrity and confidentiality of the application and can allow attackers to compromise the entire platform, potentially gaining elevated privileges and access to sensitive data. The flaw is a classic example of code injection, allowing malicious commands to be run within the platform's runtime environment.
Affected Systems
Greek Universities Network (GUnet) Open eClass Platform version 3.15 is affected. The vulnerability resides in the course module's chat feature and is likely present on any deployment of this platform using that version. All institutions hosting the platform without applying a fix are potentially at risk.
Risk and Exploitability
The CVSS score is not publicly provided, but the vulnerability offers remote code execution with minimal user interaction – an attacker only needs to send malicious content via the chat interface. Although EPSS data is unavailable and the issue is not listed in the CISA KEV catalog, the available description indicates a high exploitation potential for any user with access to the chat feature. The absence of a vendor patch at this time raises the risk level, suggesting that attackers could readily exploit the flaw if they can identify a target using the affected platform.
OpenCVE Enrichment