Skip to content

Instantly share code, notes, and snippets.

@tansique-17
Last active June 23, 2025 16:36
Show Gist options
  • Select an option

  • Save tansique-17/0776791b8edd4931216be452a6971f5e to your computer and use it in GitHub Desktop.

Select an option

Save tansique-17/0776791b8edd4931216be452a6971f5e to your computer and use it in GitHub Desktop.
CVE_2025-26198

πŸ›‘οΈ CVE Disclosure: CVE-2025-26198 β€” SQL Injection in CloudClassroom-PHP-Project

Disclosure Date: 18 June 2025
CVE ID: CVE-2025-26198
Severity: CRITICAL (CVSS 9.8)


🧩 Summary

A critical SQL Injection vulnerability exists in CloudClassroom-PHP-Project v1.0, specifically within the loginlinkadmin.php endpoint. The application directly incorporates unsanitized user inputs into SQL queries, allowing unauthenticated attackers to bypass authentication and gain full administrative access.

This issue has been assigned the identifier CVE-2025-26198. At the time of public disclosure, no official patch was available.


πŸ“¦ Affected Product

  • Vendor: Independent (mathurvishal)
  • Project: CloudClassroom-PHP-Project
  • Version: v1.0
  • File: loginlinkadmin.php
  • Vulnerable Endpoint:
    http://localhost/CloudClassroom-PHP-Project-master/loginlinkadmin.php

πŸ”¬ Vulnerability Details

The admin login mechanism uses unsanitized input directly in SQL queries without any input validation or prepared statements:

$query = "SELECT * FROM admin WHERE username='$username' AND password='$password'";

This allows for injection payloads such as:

Username: ' OR '1'='1
Password: [any value]

This bypasses authentication logic by evaluating to a true condition, thereby granting access to the admin dashboard.


πŸ“Œ CWE Classification

CWE ID Title
CWE-89 Improper Neutralization of Special Elements used in an SQL Command

πŸ“Š CVSS v3.1 Score

Score Severity Vector String
9.8 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

πŸ’₯ Impact

A successful exploitation could result in:

  • βœ… Full authentication bypass
  • πŸ”“ Unauthorized access to privileged admin features
  • πŸ› οΈ Potential data leakage or manipulation using UNION-based SQL injection
  • ⚠️ Full compromise of the backend database

πŸ§ͺ Proof of Concept (PoC)

1. Clone the Repository

git clone https://github.com/mathurvishal/CloudClassroom-PHP-Project.git

2. Host Locally

Use XAMPP/LAMP to deploy the project and navigate to:

http://localhost/CloudClassroom-PHP-Project-master/loginlinkadmin.php

3. Payload Injection

Enter the following credentials in the login form:

  • Username: ' OR '1'='1
  • Password: [any value]

You will be logged in as the first admin user, verifying successful SQL injection.


πŸ” Recommendations

  • βœ… Replace dynamic SQL queries with prepared statements (mysqli_prepare() or PDO).
  • πŸ” Perform input validation and sanitization for all user inputs.
  • 🧱 Deploy a Web Application Firewall (WAF) to block known SQL injection patterns.
  • πŸ›‘οΈ Conduct regular code audits and penetration testing for early detection.

πŸ“† Timeline

Event Date
Vulnerability Discovered 14 April 2025
Public Disclosure 18 June 2025
Patch Available ❌ Not available as of disclosure

πŸ™‹β€β™‚οΈ Credits

This vulnerability was discovered and responsibly disclosed by:

Tansique Dasari
πŸ”— GitHub
βœ‰οΈ tansique.d@gmail.com


πŸ”— References


πŸ’¬ This advisory is published independently due to lack of vendor response.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment