Description
A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: SQL Injection
Action: Apply Mitigation
AI Analysis

Impact

The vulnerability is a remote SQL injection in the CloudClassroom-PHP-Project, triggered by manipulating the gname parameter in updateguest.php. An attacker can inject arbitrary SQL through this unsanitized input, potentially allowing unauthorized access or modification of the project's database and compromising data confidentiality, integrity, or availability. The issue is categorized under CWE-74 and CWE-89, reflecting improper input handling and a direct injection flaw.

Affected Systems

The issue affects the CloudClassroom-PHP-Project from mathurvishal, with affected code up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Because the project follows a rolling-release model, specific version numbers for affected or patched releases are not available, which means any current instance may be vulnerable until an official fix is released.

Risk and Exploitability

The CVSS base score is 5.3, indicating a medium severity risk. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. The description notes that a public exploit exists and the attack can be initiated remotely, implying that exploitation can proceed without special privileges. The lack of an official patch and the rolling-release model increase the likelihood of prolonged exposure.

Generated by OpenCVE AI on September 28, 2026 at 02:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement input validation or use parameterized queries for the gname field.
  • Restrict access to updateguest.php, limiting it to administrators or authenticated users.
  • Monitor the vendor’s update channel and apply an official patch when released.

Generated by OpenCVE AI on September 28, 2026 at 02:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 01:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Title mathurvishal CloudClassroom-PHP-Project updateguest.php sql injection
First Time appeared Mathurvishal
Mathurvishal cloudclassroom-php-project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*
Vendors & Products Mathurvishal
Mathurvishal cloudclassroom-php-project
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mathurvishal Cloudclassroom-php-project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T01:00:13.301Z

Reserved: 2026-09-27T08:18:15.475Z

Link: CVE-2026-100894

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T02:17:19.260

Modified: 2026-09-28T02:17:19.260

Link: CVE-2026-100894

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T04:45:06Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')