{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-11T15:21:44.029","vulnerabilities":[{"cve":{"id":"CVE-2026-24666","sourceIdentifier":"security-advisories@github.com","published":"2026-02-03T18:16:19.690","lastModified":"2026-02-10T18:47:52.970","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"The Open eClass platform (formerly known as GUnet eClass) is a complete course management system. Prior to version 4.2, a Cross-Site Request Forgery (CSRF) vulnerability in multiple teacher-restricted endpoints allows attackers to induce authenticated teachers to perform unintended actions, such as modifying assignment grades, via crafted requests. This issue has been patched in version 4.2."},{"lang":"es","value":"La plataforma Open eClass (anteriormente conocida como GUnet eClass) es un sistema completo de gestión de cursos. Antes de la versión 4.2, una vulnerabilidad de falsificación de petición en sitios cruzados (CSRF) en múltiples puntos finales restringidos para profesores permite a los atacantes inducir a profesores autenticados a realizar acciones no intencionadas, como modificar las calificaciones de las tareas, a través de peticiones manipuladas. Este problema ha sido parcheado en la versión 4.2."}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Primary","description":[{"lang":"en","value":"CWE-352"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:gunet:open_eclass_platform:*:*:*:*:*:*:*:*","versionEndExcluding":"4.2","matchCriteriaId":"62F1C084-2C90-4AB3-A13E-28323DC385C0"}]}]}],"references":[{"url":"https://github.com/gunet/openeclass/security/advisories/GHSA-cgmh-73qg-28fm","source":"security-advisories@github.com","tags":["Exploit","Vendor Advisory"]}]}}]}