CVE-2025-26199

CRITICAL

CloudClassroom-PHP-Project 1.0 - Cleartext Transmission of Sensitive Information via HTTP Login

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2025-26199. PoCs published by tansique-17.

AI-analyzed exploit summary This repository contains a detailed writeup for CVE-2025-26199, describing an insecure password transmission vulnerability in CloudClassroom-PHP-Project v1.0. The issue involves cleartext transmission of credentials over HTTP, exposing them to interception via MitM attacks.

Description

CloudClassroom-PHP-Project v1.0 is affected by an insecure credential transmission vulnerability. The application transmits passwords over unencrypted HTTP during the login process, exposing sensitive credentials to potential interception by network-based attackers. A remote attacker with access to the same network (e.g., public Wi-Fi or compromised router) can capture login credentials via Man-in-the-Middle (MitM) techniques. If the attacker subsequently uses the credentials to log in and exploit administrative functions (e.g., file upload), this may lead to remote code execution depending on the environment.

Exploits (1)

nomisec WRITEUP
by tansique-17 · poc
https://github.com/tansique-17/CVE-2025-26199

This repository contains a detailed writeup for CVE-2025-26199, describing an insecure password transmission vulnerability in CloudClassroom-PHP-Project v1.0. The issue involves cleartext transmission of credentials over HTTP, exposing them to interception via MitM attacks.

Classification
Writeup 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: CloudClassroom-PHP-Project v1.0
No auth needed
Prerequisites: Network access to intercept HTTP traffic · Victim interaction to trigger login
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.0049
EPSS Percentile 38.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact total

Details

CWE
CWE-319
Status published
Products (1)
vishalmathur/cloudclassroom-php_project 1.0
Published Jun 18, 2025
Tracked Since Feb 18, 2026