PT-2026-99268 · Unknown · Cloudclassroom-Php Project
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
CloudClassroom-PHP-Project versions up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Description
A weakness in the file updatequery.php allows remote attackers to perform cross site scripting (XSS), which is a technique used to inject malicious scripts into web pages viewed by other users. This is achieved by manipulating the
queryx argument.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the
queryx argument in the updatequery.php file to minimize the risk of exploitation.Exploit
XSS
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloudclassroom-Php Project