Impact
A stored cross‑site scripting vulnerability exists in the registrationform.php script of the CloudClassroom‑PHP‑Project. Malicious input supplied through the FName, LName, or Addrs parameters is reflected in the page output without proper sanitization, allowing the injection of arbitrary JavaScript. This flaw is classified under CWE‑79 and CWE‑94. An attacker who exploits this flaw can execute client‑side code in the context of registered users, potentially enabling session hijacking, credential theft, defacement, or the deployment of further client‑side malware.
Affected Systems
The affected product is mathurvishal:CloudClassroom‑PHP‑Project. The advisory references a commit hash, but due to the application’s rolling‑release model, the vulnerability may exist in all current or future releases until a patch is released. The vendor has not responded to the disclosure, and no version‑specific fix is documented. Therefore, any instance of the application that includes registrationform.php remains exposed.
Risk and Exploitability
The reported CVSS score of 5.3 indicates moderate severity and the EPSS score is not available, making it difficult to gauge current exploitation likelihood. The vulnerability is not listed in the CISA KEV catalog, yet it is publicly disclosed and known to be exploitable remotely. In the absence of an official fix, the risk remains contingent on the presence of the vulnerable endpoint and the effectiveness of downstream defenses such as input validation and content‑security policies.
OpenCVE Enrichment