Description
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: SQL Injection
Action: Patch ASAP
AI Analysis

Impact

A vulnerability was found in the CloudClassroom‑PHP‑Project that allows an attacker to supply an unsanitized value in the "makeid" parameter of the "makeresult.php" script. This input is used directly in an SQL statement, enabling a classic SQL injection attack. Successfully exploited, an attacker can read, modify, or delete data stored in the database, potentially gaining full control over the application state and sensitive information.

Affected Systems

The affected product is mathurvishal CloudClassroom‑PHP‑Project up to the commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. No fixed or patched release has been published and the vendor has not responded to the disclosure. Continuous delivery with rolling releases is used, meaning that the vulnerable version may still be in production while newer code is delivered on an unknown cadence.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting that mass exploitation is not confirmed but the public exploit code is reachable. The attacker can trigger the injection remotely through an HTTP request to makeresult.php. Because an unsanitized user‑controlled variable is used directly in the query, the risk of successful exploitation remains high as long as the endpoint is accessible.

Generated by OpenCVE AI on September 28, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of the CloudClassroom‑PHP‑Project that eliminates the unsanitized use of the makeid parameter; if no fixed release exists, manually patch the code to use prepared statements or parameterized queries for all database interactions involving user input.
  • Validate the makeid input strictly to ensure it matches the expected format (e.g., numeric only) before it is used in the SQL statement, thereby mitigating the injection vector and addressing CWE-89 and CWE-74 weaknesses.
  • If upgrading or patching is not immediately possible, restrict external access to the makeresult.php endpoint with network controls (e.g., firewall rules, IP whitelisting) or remove the endpoint entirely from public exposure after evaluating business need.

Generated by OpenCVE AI on September 28, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Title mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection
First Time appeared Mathurvishal
Mathurvishal cloudclassroom-php-project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*
Vendors & Products Mathurvishal
Mathurvishal cloudclassroom-php-project
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mathurvishal Cloudclassroom-php-project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T07:45:09.138Z

Reserved: 2026-09-27T11:18:42.747Z

Link: CVE-2026-101012

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-09-28T08:16:37.147

Modified: 2026-09-28T15:16:04.793

Link: CVE-2026-101012

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T11:45:17Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')