CVE-2024-57459

A time-based SQL injection vulnerability exists in mydetailsstudent.php in the CloudClassroom PHP Project 1.0. The myds parameter does not properly validate user input, allowing an attacker to inject arbitrary SQL commands.
Configurations

Configuration 1 (hide)

cpe:2.3:a:vishalmathur:cloudclassroom-php_project:1.0:*:*:*:*:*:*:*

History

13 Jun 2025, 16:29

Type Values Removed Values Added
References () https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 - () https://gist.github.com/b0mk35h/921cfa00f9ea1af66645574537d38587 - Third Party Advisory
References () https://owasp.org/www-community/attacks/SQL_Injection - () https://owasp.org/www-community/attacks/SQL_Injection - Not Applicable
CPE cpe:2.3:a:vishalmathur:cloudclassroom-php_project:1.0:*:*:*:*:*:*:*
First Time Vishalmathur cloudclassroom-php Project
Vishalmathur
Summary
  • (es) Existe una vulnerabilidad de inyección SQL basada en tiempo en mydetailsstudent.php del CloudClassroom PHP Project 1.0. El parámetro myds no valida correctamente la entrada del usuario, lo que permite a un atacante inyectar comandos SQL arbitrarios.

02 Jun 2025, 17:15

Type Values Removed Values Added
CWE CWE-89
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.3

02 Jun 2025, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-02 16:15

Updated : 2025-06-13 16:29


NVD link : CVE-2024-57459

Mitre link : CVE-2024-57459

CVE.ORG link : CVE-2024-57459


JSON object : View

Products Affected

vishalmathur

  • cloudclassroom-php_project
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')