Impact
The vulnerability resides in an unknown function within the file updatequery.php of mathurvishal CloudClassroom‑PHP‑Project. Manipulation of the queryx argument allows an attacker to inject arbitrary scripts, enabling cross‑site scripting against users who view the reflected content. The injected code can execute in the victim’s browser, potentially leading to credential theft, session hijacking, or defacement. This weakness is categorized as CWE‑79 and is also related to CWE‑94, indicating potential improper handling of dynamic code.
Affected Systems
Affected deployments are any installations of mathurvishal CloudClassroom‑PHP‑Project based on the code base at or older than commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Specific version numbers are unavailable because the vendor follows a rolling‑release model; therefore, any instance running the affected commit is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 falls in the moderate range, suggesting that exploitation requires some level of user interaction or a trusted context. No EPSS score is published, but the public release of exploits indicates that attackers can target vulnerable sites remotely. The vulnerability is not listed in CISA’s KEV catalog, yet the availability of exploit code and the ability to execute scripts in a victim’s browser elevate the real‑world risk for exposed web applications.
OpenCVE Enrichment