Executive brief
CloudClassroom-PHP-Project is an educational classroom management application. A cross-site request forgery vulnerability in the application allows attackers to perform unauthorized actions on behalf of authenticated users by tricking them into visiting a malicious webpage. The exploit is publicly available, increasing the risk of widespread attack.
Technical details
The vulnerability is a cross-site request forgery (CSRF) flaw in an unknown function of CloudClassroom-PHP-Project that can be exploited remotely without authentication. The vulnerable component lacks CSRF token validation, allowing attackers to forge requests and execute actions with the privileges of a logged-in user. No vendor patch is available.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-27: disclosed