Sceawere
Vulnerability Detail
CVE-2026-100874UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in CloudClassroom-PHP-Project
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 13h ago
- Vendor
- mathurvishal
- Product
- CloudClassroom-PHP-Project
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This affects an unknown function of the file addnewstudent.php. This manipulation causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-27T19:16:53.920Z",
"pubdate": "2026-09-27T19:16:53.920Z",
"executiveSummary": "A critical SQL injection (SQLi) vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, specifically impacting the addnewstudent.php file. This vulnerability allows remote, unauthenticated attackers to manipulate database queries by injecting malicious SQL statements through unsanitized input parameters.\nSuccessful exploitation of this flaw can result in unauthorized access to the application's backend database, potentially leading to the exposure, modification, or deletion of sensitive student records and administrative data. The vulnerability arises from improper neutralization of special elements used in an SQL command within the source code.\nGiven that public exploit code exists and the vendor has remained unresponsive, the risk to deployments is high. The nature of the vulnerability facilitates remote exploitation without the need for prior authentication, enabling attackers to compromise the integrity and confidentiality of the entire database layer. Because the project utilizes a rolling release model, users are urged to audit their specific codebases against the known vulnerable commit hash 5dadec098bfbbf3300d60c3494db3fb95b66e7be to determine exposure status.",
"technicalDetails": "The vulnerability resides in the addnewstudent.php component of the CloudClassroom-PHP-Project, which fails to implement robust input validation or parameterized queries when processing user-supplied data intended for database interaction. The root cause is the inclusion of untrusted user input directly into SQL query strings, which permits an attacker to alter the query's logic and structure.\nExploitation is achieved by supplying a crafted payload through input vectors processed by addnewstudent.php. When the application receives these inputs, it concatenates the unsanitized data into a pre-defined SQL statement. An attacker can inject SQL syntax such as single quotes, UNION operators, or comment delimiters to break out of the intended query context. By doing so, the attacker can execute arbitrary SQL commands with the privileges of the database user account configured for the application.\nThe attack flow typically involves the following steps: 1) The attacker identifies the vulnerable input parameters within the addnewstudent.php interface. 2) The attacker submits a malicious string containing SQL commands designed to manipulate the query, such as ' OR '1'='1 to bypass authentication or extract data via UNION-based injection. 3) The backend server processes the unsanitized input and executes the injected SQL statement against the underlying database management system. 4) The database engine returns the results of the malicious query to the attacker, providing unauthorized access to data or control over the database state.\nThis vulnerability is classified as a remote SQL injection attack, meaning it can be initiated over a network without requiring a local foothold. The impact is significant, as successful injection can lead to complete database compromise, including the exfiltration of personally identifiable information (PII) stored within the system, unauthorized administrative account creation, or total loss of data integrity. The lack of parameterized queries or prepared statements in the affected file constitutes a major security oversight in the application's data access layer. Because the project follows a rolling release model and no official patch has been provided by the vendor, deployments remain in a state of continuous risk unless manual code-level remediation is applied."
}