Description
Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.
Published: 2026-09-29
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution via Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

A stored cross‑site scripting (XSS) flaw exists in the user registration form of the Greek Universities Network (GUnet) Open eClass Platform v.3.15. The attacker can submit malicious JavaScript through the last name, first name, and username input fields, and the payload is persisted in the database. When a logged‑in user views their profile or any page displaying the stored data, the malicious code executes in the user's browser with the privileges of that user, potentially allowing session hijacking, credential theft, or further exploitation of the web application.

Affected Systems

All installations of the GUnet Open eClass Platform version 3.15 are vulnerable. No other versions or vendors are explicitly listed as affected.

Risk and Exploitability

The vulnerability can be exploited remotely by crafting a registration request that contains malicious script. Because the flaw is stored, no interactive steps are required after the initial injection; the payload remains until the data is modified or expired. No EPSS score is available and the issue is not listed in the CISA KEV catalog, but stored XSS is a well‑known and widely leveraged attack vector. The CVSS score is not disclosed in the provided data, so a precise severity estimate cannot be given here. The lack of disclosure about mitigation or patch availability suggests that the exploitation cost is low for an attacker who can submit a registration request.

Generated by OpenCVE AI on September 30, 2026 at 04:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade GUnet Open eClass Platform to a version that sanitizes or escapes user name inputs before storing them.
  • If a patch is unavailable, implement server‑side validation to strip or encode disallowed HTML and JavaScript from the last name, first name, and username fields before persisting them.
  • Apply output‑context encoding when rendering these fields in any web page so that any remaining markup is rendered harmless.

Generated by OpenCVE AI on September 30, 2026 at 04:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 30 Sep 2026 04:45:00 +0000

Type Values Removed Values Added
Title Stored Cross‑Site Scripting in GUnet Open eClass Platform User Registration Allows Remote Code Execution
Weaknesses CWE-79

Tue, 29 Sep 2026 19:45:00 +0000

Type Values Removed Values Added
Description Cross Site Scripting vulnerability in Greek Universities Network (GUnet) Open eClass Platform v.3.15 allows a remote attacker to execute arbitrary code via the last name, first name, and username parameters in the user registration functionality.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-29T19:33:20.180Z

Reserved: 2024-03-27T00:00:00.000Z

Link: CVE-2024-31027

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-29T20:17:08.700

Modified: 2026-09-29T20:17:08.700

Link: CVE-2024-31027

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-30T04:30:11Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')