Executive brief
CloudClassroom-PHP-Project is a student management application with a public registration form. An unauthenticated attacker can inject malicious scripts into student registration fields (first name, last name, address) that are executed when other users view student details, enabling account takeover, session hijacking, or credential theft.
Technical details
Stored cross-site scripting vulnerability in registrationform.php where user-supplied input parameters (FName, LName, Addrs) are stored without sanitization and reflected in studentdetails.php without proper encoding. An unauthenticated attacker can inject JavaScript payloads via self-registration that execute in the browsers of users viewing student profiles. The vulnerability requires no authentication or user interaction beyond normal application use.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-27: disclosed
- 2026-09-27: advisory: Public advisory released; vendor did not respond to early disclosure notification