Impact
A flaw in the CloudClassroom-PHP-Project’s viewresult.php file allows an attacker to inject arbitrary SQL by manipulating the seno parameter. The injection could enable the attacker to read, modify, or delete database contents. The flaw is a typical application-layer weakness identified as CWE-74 and includes functional aspects of CWE-89.
Affected Systems
The vulnerability affects the mathurvishal CloudClassroom-PHP-Project, specifically any release up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. No earlier patches are available, and there is no information provided about patches in later releases.
Risk and Exploitability
The CVSS base score of 6.9 indicates a moderate risk level. The EPSS score is not provided, and the vulnerability is not listed in the CISA KEV catalog, but public exploitation code is available. Attackers can exploit the flaw remotely through crafted HTTP requests to the viewresult.php endpoint. Due to the lack of an immediate remedy notice from the vendor and public evidence of exploitation, the risk of compromise remains significant.
OpenCVE Enrichment