CVE‑2024‑31026 – HTML Injection in GUnet Open eClass
Date of Report: 24 / 3 / 2024
Description
GUnet Open eClass ≤ 3.15 is vulnerable to HTML injection via the chat input field inside any course module.
Impact
Attackers can:
- Inject deceptive content or phishing pages
- Auto‑redirect users to malicious sites
- Seed malware downloads
Proof of Concept
https://www.youtube.com/watch?v=-DwkPVmTrfY
Affected Component
chat input field (modules/chat/).
Mitigation
Escape or strip HTML, or render chat content with a whitelist sanitizer.
Written on March 24, 2024
