Vulnerability CVE-2024-33253


Published: 2024-06-13   Modified: 2024-06-14

Description:
Cross-site scripting (XSS) vulnerability in GUnet OpenEclass E-learning Platform version 3.15 and before allows a authenticated privileged attacker to execute arbitrary code via the title and description fields of the badge template editing function.

 References:
https://github.com/FreySolarEye/CVE/blob/master/GUnet%20OpenEclass%20E-learning%20platform%203.15%20-%20%27certbadge.php%27%20Stored%20Cross%20Site%20Scripting

Copyright 2026, cxsecurity.com

 

Back to Top