VYPR

Cloudclassroom

by Vishalmathur

CVEs (2)

  • CVE-2025-50867MedJul 31, 2025
    risk 0.42cvss 6.5epss 0.00

    A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.

  • CVE-2025-50866MedJul 31, 2025
    risk 0.40cvss 6.1epss 0.00

    CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser,…