Open eClass Broken Access Control Vulnerability Allows Unauthorized Course Unit Creation

Vulnerability

A broken access control vulnerability has been identified in the Open eClass platform, prior to version 4.2. This vulnerability allows authenticated students to create new course units, a privilege typically reserved for instructors or administrators. The issue arises from the application's failure to enforce proper access controls at the '/modules/units/index.php' endpoint, enabling students to manipulate course structures inappropriately and potentially disrupt course integrity.

Impact

Exploitation of this vulnerability could lead to unauthorized creation of course units by students, bypassing the intended role-based access controls and potentially disrupting the management and integrity of course content.

Reproduction

To reproduce this vulnerability, authenticate as a user with student privileges. Then, send a request to the '/modules/units/index.php' endpoint with the required parameters, such as unit title and description. The request will be processed successfully, and the new unit will be created, demonstrating the access control flaw.

Remediation

Users are advised to update to Open eClass version 4.2 or later, where this vulnerability has been patched.

Added: Feb 3, 2026, 6:21 PM
Updated: Feb 3, 2026, 6:21 PM

Vulnerability Rating

Custom Algorithm
spread
1.9
impact
0.6
exploitability
6.6
remediation
7.7
relevance
2.7
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.