CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.
History

Fri, 20 Jun 2025 16:00:00 +0000

Type Values Removed Values Added
Description An issue in CloudClassroom PHP Project v.1.0 allows a remote attacker to execute arbitrary code via the cleartext submission of passwords. CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.
References

Wed, 18 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-319
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 18 Jun 2025 19:30:00 +0000

Type Values Removed Values Added
Description An issue in CloudClassroom PHP Project v.1.0 allows a remote attacker to execute arbitrary code via the cleartext submission of passwords.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2025-06-18T00:00:00.000Z

Updated: 2025-06-20T15:48:36.524Z

Reserved: 2025-02-07T00:00:00.000Z

Link: CVE-2025-26199

cve-icon Vulnrichment

Updated: 2025-06-18T19:52:26.770Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-18T20:15:19.667

Modified: 2025-06-23T20:16:59.783

Link: CVE-2025-26199

cve-icon Redhat

No data.