Impact
The CloudClassroom-PHP-Project contains a vulnerability in the updatedetailsfromstudent.php endpoint where manipulation of the eno parameter allows an attacker to inject arbitrary SQL. This flaw enables a remote attacker to craft a malicious request that is executed directly against the database, potentially exposing or altering sensitive data. The weakness is a classic SQL Injection (CWE‑89) coupled with uncontrolled data inclusion (CWE‑74).
Affected Systems
Affected instances of the CloudClassroom-PHP-Project with the repository hash 5dadec098bfbbf3300d60c3494db3fb95b66e7be are impacted. No specific version patches are publicly available, and the vendor has provided no response to the disclosure. The lack of a precise version range or fixed release means any deployment prior to the disclosure could be vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity, while the EPSS score is not available, leaving the exploit likelihood uncertain. The vulnerability is listed as not being in the CISA KEV catalog, but it is publicly disclosed and can be exploited remotely. Without an advisory from the vendor, system owners should treat this flaw as a potential risk for data leakage or modification until a mitigated version is obtained.
OpenCVE Enrichment