Executive brief
CloudClassroom-PHP-Project is a PHP-based classroom management application. A missing authentication vulnerability in the loginlinkstudent.php file allows attackers to manipulate the umail parameter and bypass login controls, potentially gaining unauthorized access to student accounts and educational data without valid credentials.
Technical details
The vulnerability exists in loginlinkstudent.php where the umail parameter is processed without proper authentication validation, allowing direct manipulation to bypass login checks. Remote exploitation is possible without authentication or user interaction required. An attacker can gain unauthorized access to student accounts and associated classroom data.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-27: disclosed
- other: Exploit code made public; vendor did not respond to early disclosure notification