Impact
An unknown function in the mathurvishal CloudClassroom‑PHP‑Project allows attackers to forge state‑changing web requests without user interaction. The flaw enables a traditional cross‑site request forgery (CWE‑352), potentially giving an attacker the ability to modify or delete data, perform privileged actions, or elevate privileges within the application (CWE‑862). Because a victim’s browser can be tricked into sending authenticated requests that the server treats as authorized, the impact includes data tampering, unauthorized privilege escalation, and loss of integrity for a wide range of operations.
Affected Systems
All installations of mathurvishal CloudClassroom‑PHP‑Project are affected, up to the commit hash 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The product does not use explicit versioning, so any instance that predates or matches that commit is considered at risk. No patch or unaffected release information is available, and the vendor did not respond to the disclosure.
Risk and Exploitability
The CVSS base score of 5.3 indicates moderate severity. The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The attack can be launched remotely, and the exploit is publicly documented, so it is likely that a malicious actor could locate and exploit vulnerable instances once identified. With no official fix, the likelihood of exploitation remains non‑negligible, but the exact probability cannot be quantified without EPSS data. The attack vector is inferred to be via a malicious link or embedded request that forces a user’s browser to submit a forged request to a protected endpoint.
OpenCVE Enrichment