Vulnerability Description
CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject arbitrary JavaScript code that executes in the context of the user s browser, potentially leading to session hijacking or phishing attacks.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vishalmathur | Cloudclassroom | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/SacX-7/CVE-2025-50866Third Party Advisory
FAQ
What is CVE-2025-50866?
CVE-2025-50866 is a vulnerability with a CVSS score of 6.1 (MEDIUM). CloudClassroom-PHP-Project 1.0 contains a reflected Cross-site Scripting (XSS) vulnerability in the email parameter of the postquerypublic endpoint. Improper sanitization allows an attacker to inject ...
How severe is CVE-2025-50866?
CVE-2025-50866 has been rated MEDIUM with a CVSS base score of 6.1/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50866?
Check the references section above for vendor advisories and patch information. Affected products include: Vishalmathur Cloudclassroom.