A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
References
Link | Resource |
---|---|
https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 | Third Party Advisory |
https://owasp.org/www-community/attacks/SQL_Injection | Not Applicable |
Configurations
History
13 Jun 2025, 16:29
Type | Values Removed | Values Added |
---|---|---|
References | () https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 - Third Party Advisory | |
References | () https://owasp.org/www-community/attacks/SQL_Injection - Not Applicable | |
CPE | cpe:2.3:a:vishalmathur:cloudclassroom-php_project:1.0:*:*:*:*:*:*:* | |
First Time |
Vishalmathur cloudclassroom-php Project
Vishalmathur |
|
Summary |
|
02 Jun 2025, 17:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-89 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.3 |
02 Jun 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-02 16:15
Updated : 2025-06-13 16:29
NVD link : CVE-2024-57459
Mitre link : CVE-2024-57459
CVE.ORG link : CVE-2024-57459
JSON object : View
Products Affected
vishalmathur
- cloudclassroom-php_project
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')