PT-2025-31560 · Unknown · Cloudclassroom-Php Project
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
CloudClassroom-PHP-Project version 1.0
Description
The software contains a reflected Cross-site Scripting (XSS) vulnerability in the
email parameter of the /postquerypublic API endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user’s browser, potentially leading to session hijacking or phishing attacks.Recommendations
Ensure proper sanitization of the
email parameter within the /postquerypublic API endpoint.Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudclassroom-Php Project