CVE-2025-50867
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
- Affected products
- Cloudclassroom-Php Project
- Vishalmathur Cloudclassroom
- = 1.0
- CVSS 3.1
- 6.5 MEDIUM
- EPSS
- 0.2% (15th percentile)
- Weakness
- CWE-89
- NVD status
- Analyzed
- Published
- 2025-07-31
CVE-2025-50867 at NVD
1 known exploit for CVE-2025-50867
Proof-of-concept code and exploit modules indexed by Sploitus