Description
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-28
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote SQL Injection
Action: Assess Impact
AI Analysis

Impact

This vulnerability is an SQL injection flaw located in an unknown function of updateresultdetails.php. By manipulating the editid argument, an attacker can inject arbitrary SQL into the database query. The injection can allow the attacker to read, modify, or delete data in the database, potentially compromising user information or system integrity. This is a classic database injection problem and can affect confidentiality and integrity of the application data.

Affected Systems

The vulnerability is present in mathurvishal’s CloudClassroom-PHP-Project for versions up to the commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The product does not use versioning and the vendor did not respond to the disclosure, so no unaffected releases are identified. Any deployment of the application that includes this commit or earlier is potentially vulnerable.

Risk and Exploitability

The CVSS score is 6.9, indicating a moderate severity. EPSS information is unavailable and the vulnerability is not listed in CISA’s KEV catalog, suggesting it has not been widely exploited yet. The attack can be performed remotely via the web interface by supplying a crafted editid value, and no authentication requirements are mentioned in the description, so it is likely exploitable by unauthenticated or low-privileged users.

Generated by OpenCVE AI on September 28, 2026 at 09:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace the raw SQL query with a prepared statement or a parameterized query to eliminate direct injection points.
  • Validate the editid parameter to accept only numeric values and reject any non‑numeric input.
  • Restrict database user privileges to the minimum required for the application functions, limiting damage if an injection occurs.

Generated by OpenCVE AI on September 28, 2026 at 09:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 28 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 28 Sep 2026 08:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Title mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection
First Time appeared Mathurvishal
Mathurvishal cloudclassroom-php-project
Weaknesses CWE-74
CWE-89
CPEs cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*
Vendors & Products Mathurvishal
Mathurvishal cloudclassroom-php-project
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Mathurvishal Cloudclassroom-php-project
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-28T11:05:12.795Z

Reserved: 2026-09-27T11:18:46.398Z

Link: CVE-2026-101013

cve-icon Vulnrichment

Updated: 2026-09-28T11:05:08.328Z

cve-icon NVD

Status : Received

Published: 2026-09-28T08:16:37.313

Modified: 2026-09-28T12:17:35.830

Link: CVE-2026-101013

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T10:30:14Z

Weaknesses
  • CWE-74

    Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

  • CWE-89

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')