A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 | Third Party Advisory |
https://owasp.org/www-community/attacks/SQL_Injection | Not Applicable |
Configurations
History
13 Jun 2025, 16:29
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:vishalmathur:cloudclassroom-php_project:1.0:*:*:*:*:*:*:* | |
References | () https://owasp.org/www-community/attacks/SQL_Injection - Not Applicable | |
References | () https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 - Third Party Advisory | |
First Time |
Vishalmathur cloudclassroom-php Project
Vishalmathur |
02 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-02 16:15
Updated : 2025-06-13 16:29
NVD link : CVE-2024-57459
Mitre link : CVE-2024-57459
JSON object : View
Products Affected
vishalmathur
- cloudclassroom-php_project
CWE
No CWE.