CVE‑2024‑31026 – HTML Injection in GUnet Open eClass

Date of Report: 24 / 3 / 2024

Description

GUnet Open eClass ≤ 3.15 is vulnerable to HTML injection via the chat input field inside any course module.

Impact

Attackers can:

  • Inject deceptive content or phishing pages
  • Auto‑redirect users to malicious sites
  • Seed malware downloads

Proof of Concept

https://www.youtube.com/watch?v=-DwkPVmTrfY

Affected Component

chat input field (modules/chat/).

Mitigation

Escape or strip HTML, or render chat content with a whitelist sanitizer.

Written on March 24, 2024