Impact
A vulnerability was found in the CloudClassroom‑PHP‑Project that allows an attacker to supply an unsanitized value in the "makeid" parameter of the "makeresult.php" script. This input is used directly in an SQL statement, enabling a classic SQL injection attack. Successfully exploited, an attacker can read, modify, or delete data stored in the database, potentially gaining full control over the application state and sensitive information.
Affected Systems
The affected product is mathurvishal CloudClassroom‑PHP‑Project up to the commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. No fixed or patched release has been published and the vendor has not responded to the disclosure. Continuous delivery with rolling releases is used, meaning that the vulnerable version may still be in production while newer code is delivered on an unknown cadence.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that mass exploitation is not confirmed but the public exploit code is reachable. The attacker can trigger the injection remotely through an HTTP request to makeresult.php. Because an unsanitized user‑controlled variable is used directly in the query, the risk of successful exploitation remains high as long as the endpoint is accessible.
OpenCVE Enrichment