Vulnerability Description
A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Vishalmathur | Cloudclassroom | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/SacX-7/CVE-2025-50867Third Party Advisory
FAQ
What is CVE-2025-50867?
CVE-2025-50867 is a vulnerability with a CVSS score of 6.5 (MEDIUM). A SQL Injection vulnerability exists in the takeassessment2.php endpoint of the CloudClassroom-PHP-Project 1.0, where the Q5 POST parameter is directly embedded in SQL statements without sanitization.
How severe is CVE-2025-50867?
CVE-2025-50867 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-50867?
Check the references section above for vendor advisories and patch information. Affected products include: Vishalmathur Cloudclassroom.