PT-2025-23534 · Unknown · Cloudclassroom-Php Project

Published

2025-06-02

·

Updated

2025-06-13

·

CVE-2024-57459

CVSS v3.1

7.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions CloudClassroom PHP Project version 1.0
Description A time-based SQL injection issue exists due to improper validation of user input in the myds parameter of the mydetailsstudent.php file. This allows an attacker to inject arbitrary SQL commands.
Recommendations For CloudClassroom PHP Project version 1.0, consider validating and sanitizing user input for the myds parameter to prevent SQL injection attacks. As a temporary workaround, restrict access to the mydetailsstudent.php file until a proper fix is implemented.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-57459

Affected Products

Cloudclassroom-Php Project