Sceawere

Vulnerability Detail

CVE-2026-100873UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CloudClassroom-PHP Cross-Site Request Forgery

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
13h ago
Vendor
mathurvishal
Product
CloudClassroom-PHP-Project
Attack Type
Cross-Site Request Forgery
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-09-27T19:16:53.720Z",
  "pubdate": "2026-09-27T19:16:53.720Z",
  "executiveSummary": "A Cross-Site Request Forgery (CSRF) vulnerability exists in the mathurvishal CloudClassroom-PHP-Project, affecting versions up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be.\nThis security flaw allows a remote, unauthenticated attacker to force a victim user to execute unintended actions on the web application without their knowledge or consent.\nThe vulnerability stems from an absence of proper anti-CSRF tokens or validation mechanisms within the application's state-changing operations.\nSuccessful exploitation can result in the unauthorized performance of sensitive actions, such as administrative modifications, account takeovers, or data manipulation, depending on the privileges of the victim.\nGiven that the exploit is public and the vendor remains unresponsive, the risk to users is significant, as attackers can leverage the victim's authenticated session to bypass authorization controls.\nThere are currently no official patches available for this product, necessitating immediate independent defensive measures.",
  "technicalDetails": "The vulnerability is a classic Cross-Site Request Forgery (CSRF) weakness located within the mathurvishal CloudClassroom-PHP-Project. The core issue is the lack of cryptographically secure, unique, and unpredictable tokens associated with state-changing HTTP requests.\nIn a CSRF attack, the application fails to verify whether a request initiated by a user was intentionally triggered by the user's interaction with the application's interface or if it was maliciously forced by a third party.\nThe attack flow proceeds as follows: 1) An attacker identifies a state-changing function within the application that does not require a unique, secret token for validation. 2) The attacker crafts a malicious payload, typically embedded in an external website, an email, or an iframe, which automatically triggers a forged HTTP request to the target CloudClassroom-PHP application when a logged-in user visits the attacker-controlled resource. 3) The victim's web browser, maintaining an active session with the CloudClassroom-PHP application via session cookies, automatically includes these credentials with the forged request. 4) The application, unable to distinguish the forged request from a legitimate one, processes the action under the victim's authorization level.\nThis exploit is performed remotely and does not require the attacker to have direct access to the application's server-side code. The primary requirement is that the victim must possess an active session within the vulnerable application at the time of the attack. Since the application fails to implement modern CSRF protection mechanisms like Synchronizer Tokens (ST) or SameSite cookie attributes, the security boundary is effectively bypassed.\nThe scope of impact is contingent upon the permissions held by the victim. If an administrator visits the attacker's site while logged into the CloudClassroom-PHP-Project, the attacker could theoretically perform high-privileged operations, such as creating new administrative accounts, modifying application configurations, or deleting sensitive classroom data.\nAs the software lacks a formal versioning system, the affected range is defined by the repository commit hash up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The vulnerability is persistent due to the design flaw, and without vendor intervention, the application remains exposed to public exploitation vectors."
}
CVE-2026-100873: CloudClassroom-PHP Cross-Site Request Forgery (MEDIUM Severity, CVSS: 4.3) | Sceawere