PT-2025-31560 · Unknown · Cloudclassroom-Php Project

·

CVE-2025-50866

·

Published

2025-07-31

·

Updated

2025-07-31

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CloudClassroom-PHP-Project version 1.0
Description The software contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the /postquerypublic API endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user’s browser, potentially leading to session hijacking or phishing attacks.
Recommendations Ensure proper sanitization of the email parameter within the /postquerypublic API endpoint.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-50866

Affected Products

Cloudclassroom-Php Project