Impact
The vulnerability is a remote SQL injection in the CloudClassroom-PHP-Project, triggered by manipulating the gname parameter in updateguest.php. An attacker can inject arbitrary SQL through this unsanitized input, potentially allowing unauthorized access or modification of the project's database and compromising data confidentiality, integrity, or availability. The issue is categorized under CWE-74 and CWE-89, reflecting improper input handling and a direct injection flaw.
Affected Systems
The issue affects the CloudClassroom-PHP-Project from mathurvishal, with affected code up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Because the project follows a rolling-release model, specific version numbers for affected or patched releases are not available, which means any current instance may be vulnerable until an official fix is released.
Risk and Exploitability
The CVSS base score is 5.3, indicating a medium severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The description notes that a public exploit exists and the attack can be initiated remotely, implying that exploitation can proceed without special privileges. The lack of an official patch and the rolling-release model increase the likelihood of prolonged exposure.
OpenCVE Enrichment