CVE-2025-46178
Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.
- Affected products
- Cloudclassroom-Php Project
- Vishalmathur Cloudclassroom-php Project
- = 1.0
- CVSS 3.1
- 6.1 MEDIUM
- EPSS
- 0.4% (29th percentile)
- Weakness
- CWE-79
- NVD status
- Analyzed
- Published
- 2025-06-09
CVE-2025-46178 at NVD
1 known exploit for CVE-2025-46178
Proof-of-concept code and exploit modules indexed by Sploitus