
CVE-2026-22241
Open eClass (also known as GUnet eClass), a widely used open-source Learning Management System (LMS), contains a critical Unrestricted File Upload vulnerability in its Theme Import feature.
An authenticated administrator can upload a malicious ZIP file, leading to Remote Code Execution (RCE) on the server.
| Version | Status |
|---|---|
| Open eClass < 4.2 | Vulnerable |
| Open eClass ≥ 4.2 | Patched |
The vulnerability exists due to insufficient validation and sanitization of uploaded ZIP archives during the theme import process. Malicious files (such as PHP webshells) can be written to the web-accessible directory.
This repository is intended for educational and research purposes only.
The information provided is for helping security researchers and system administrators understand and patch the vulnerability.
Unauthorized exploitation against systems you do not own is illegal.
Made for Security Awareness & Research
⭐ If this helped you, please star the repository!