Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-46178 — Documentation and proof-of-concept for a reflected XSS vulnerability in CloudClassroom PHP Project, including attack vectors and mitigation recommendations. | Kitploit
Tools/GitHubGitHub/sacx-7/cve-2025-46178
Vulnerability AnalysisWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubsacx-7/cve-2025-46178

CVE-2025-46178

Documentation and proof-of-concept for a reflected XSS vulnerability in CloudClassroom PHP Project, including attack vectors and mitigation recommendations.

View Repository
11 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-46178

Cross-Site Scripting (XSS) vulnerability exists in askquery.php via the eid parameter in the CloudClassroom PHP Project. This allows remote attackers to inject arbitrary JavaScript in the context of a victim s browser session by sending a crafted URL, leading to session hijacking or defacement.

Additional Information The payload demonstrates successful JavaScript execution using the alert(9734) function. Input is not being properly sanitized or encoded before rendering, exposing the application to reflected XSS.

To mitigate this issue:

Use server-side input validation Encode output properly (especially for HTML contexts) Consider using security libraries like OWASP ESAPI or frameworks with built-in XSS protection

Vulnerability Type

Cross Site Scripting (XSS)

Vendor of Product

https://github.com/mathurvishal/CloudClassroom-PHP-Project

Affected Product Code Base

https://github.com/mathurvishal/CloudClassroom-PHP-Project 1.0 - https://github.com/mathurvishal/CloudClassroom-PHP-Project 1.0

Affected Component

askquery.php, eid GET parameter, frontend HTML rendering logic

Attack Vectors

An attacker can inject malicious JavaScript payloads via the eid GET parameter. When a victim visits a crafted URL, the script executes in their browser, potentially stealing cookies or performing unauthorized actions.

  1. click on http://localhost/CloudClassroom-PHP-Project-master/askquery.php?eid=testing%40example.com%27%22()%26%25%3Czzz%3E%3CScRiPt%20%3Ealert(9734)%3C/ScRiPt%3E
  2. you will see alert

Reference https://owasp.org/www-community/attacks/xss/


Discoverer : saurabh

linkdin : https://www.linkedin.com/in/saurabh-b294b21aa/

Download Tool