cvedb.io
CVE-2025-26199
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2025-06-18T20:15:19.667 · Last modified 2026-06-17T09:01:30.830

Summary

CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.

Affected products

vishalmathur — cloudclassroom-php_project

Does this affect you?

Add your gear to cvedb and we'll alert you only when vishalmathur ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.