CVE-2026-22241 affects the Open eClass platform (formerly GUnet eClass) prior to version 4.2. The vulnerability is in the theme import functionality, where ZIP archives are processed without proper validation or sanitization of the files contained within the archive. An attacker with administrative privileges can upload a crafted archive containing arbitrary files and cause those files to be written to the server file system. Because this can include executable server-side code placed in a web-accessible location, successful exploitation can result in remote code execution on the web server.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
Repository is a small lab + PoC for CVE-2026-22241 described as an unrestricted file upload leading to RCE in Open eClass/OpenClass Educational Infrastructure. Structure/purpose: - README.md: Step-by-step instructions to build a Dockerized Open eClass 4.0.1 environment, then exploit an admin-only theme upload feature by uploading a ZIP (poc.zip) containing a PHP webshell. Provides example URLs to trigger command execution. - docker-compose.yml: Defines a two-container lab (mysql:8.0 and php:8.3-apache) with the application mounted into /var/www/html and exposed on host port 8080. - evil.php: The actual payload (minimal PHP webshell) executing shell commands from the 'cmd' query parameter. Exploit capability: - Achieves remote command execution over HTTP after successful upload by requesting /courses/theme_data/evil.php?cmd=<command>. - No automated exploitation code is included; exploitation is manual via the web UI upload flow. The included payload is a basic webshell (no persistence, no reverse shell, no obfuscation).
Repository contains a single Python exploit script (CVE-2026-22241.py), a README, requirements.txt, and GPLv3 LICENSE. The exploit targets Open eClass versions prior to 4.2 (CVE-2026-22241), abusing an unrestricted file upload in the admin Theme Import feature. Core flow: 1) Authenticates to the target using provided admin credentials by POSTing to /?login_page=1 (with Referer /main/login_form.php?next=%2Fmain%2Fportfolio.php). 2) Creates a local ZIP (poc.zip) containing a PHP webshell (evil.php) that executes system($_REQUEST['cmd']). 3) Fetches /modules/admin/theme_options.php to confirm admin access and scrape a CSRF token from an input named token. 4) Uploads the ZIP to /modules/admin/theme_options.php as themeFile, leveraging the vulnerable import mechanism to place the PHP file under /courses/theme_data/. 5) Provides an interactive pseudo-shell that sends commands to /courses/theme_data/evil.php?cmd=<cmd> and prints output. 6) On 'quit', attempts cleanup by invoking rm evil.php through the webshell. The repository is an operational RCE exploit (not just detection): it includes a working payload, automated token handling, upload logic, and an interactive command loop. No external C2 infrastructure is embedded; all network interaction is with the user-supplied target base URL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
3 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.