Impact
A vulnerability in the loginlinkstudent.php file of the CloudClassroom-PHP-Project allows an attacker to manipulate the "umail" argument and bypass authentication. The flaw results in missing authentication checks, enabling remote exploitation without needing valid credentials. This can compromise the confidentiality and integrity of student data and potentially allow other privileged actions within the application.
Affected Systems
The affected product is mathurvishal CloudClassroom-PHP-Project, specifically versions up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. No exact release or patch information is available due to the product’s rolling‑release model, and the vendor has not responded to the disclosure.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity impact. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote, involving crafted HTTP requests that alter the "umail" parameter to circumvent login checks. Given the lack of a current fix, the risk remains until a vendor patch or mitigation is applied.
OpenCVE Enrichment