Impact
The Open eClass platform contains a business logic flaw that allows authenticated students to mark themselves as present in attendance activities that have already expired by directly accessing a crafted URL. This flaw enables dishonest attendance, potentially affecting academic integrity and any systems that tie attendance to grading or benefits. The weakness is classified as CWE-841, indicating improper authorization.
Affected Systems
The vulnerability impacts the Open eClass platform (formerly GUnet eClass) sold by gunet. All releases prior to version 4.2 are affected, while version 4.2 and later contain the fix. Administrators should verify that their installations run 4.2 or newer.
Risk and Exploitability
The CVSS score is 4.3, reflecting moderate severity. The EPSS score is below 1%, suggesting a low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a remote authenticated student who crafts the URL; the attack requires valid student credentials and can only affect courses where the activity has already expired. The impact is limited to attendance records for the affected courses, but repeated use could undermine grading integrity.
OpenCVE Enrichment