Impact
A stored cross‑site scripting (XSS) flaw exists in the user registration form of the Greek Universities Network (GUnet) Open eClass Platform v.3.15. The attacker can submit malicious JavaScript through the last name, first name, and username input fields, and the payload is persisted in the database. When a logged‑in user views their profile or any page displaying the stored data, the malicious code executes in the user's browser with the privileges of that user, potentially allowing session hijacking, credential theft, or further exploitation of the web application.
Affected Systems
All installations of the GUnet Open eClass Platform version 3.15 are vulnerable. No other versions or vendors are explicitly listed as affected.
Risk and Exploitability
The vulnerability can be exploited remotely by crafting a registration request that contains malicious script. Because the flaw is stored, no interactive steps are required after the initial injection; the payload remains until the data is modified or expired. No EPSS score is available and the issue is not listed in the CISA KEV catalog, but stored XSS is a well‑known and widely leveraged attack vector. The CVSS score is not disclosed in the provided data, so a precise severity estimate cannot be given here. The lack of disclosure about mitigation or patch availability suggests that the exploitation cost is low for an attacker who can submit a registration request.
OpenCVE Enrichment