Impact
This vulnerability is an SQL injection flaw located in an unknown function of updateresultdetails.php. By manipulating the editid argument, an attacker can inject arbitrary SQL into the database query. The injection can allow the attacker to read, modify, or delete data in the database, potentially compromising user information or system integrity. This is a classic database injection problem and can affect confidentiality and integrity of the application data.
Affected Systems
The vulnerability is present in mathurvishal’s CloudClassroom-PHP-Project for versions up to the commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The product does not use versioning and the vendor did not respond to the disclosure, so no unaffected releases are identified. Any deployment of the application that includes this commit or earlier is potentially vulnerable.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate severity. EPSS information is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. The attack can be performed remotely via the web interface by supplying a crafted editid value, and no authentication requirements are mentioned in the description, so it is likely exploitable by unauthenticated or low-privileged users.
OpenCVE Enrichment