Sceawere
Vulnerability Detail
CVE-2026-100876UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CloudClassroom-PHP-Project Authentication Bypass Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 6.3
- Creation Date
- 12h ago
- Vendor
- mathurvishal
- Product
- CloudClassroom-PHP-Project
- Attack Type
- Missing Authentication
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file loginlinkstudent.php. Performing a manipulation of the argument umail results in missing authentication. Remote exploitation of the attack is possible. The exploit has been made public and could be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "6.3",
"pubDate": "2026-09-27T20:16:48.960Z",
"pubdate": "2026-09-27T20:16:48.960Z",
"executiveSummary": "A critical authentication bypass vulnerability exists in the mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be.\nThe vulnerability resides within the loginlinkstudent.php file, where improper handling of the 'umail' input parameter allows unauthorized users to circumvent standard authentication mechanisms.\nThis flaw is categorized as a missing authentication vulnerability, which poses a severe risk to the integrity and confidentiality of the platform.\nThe vulnerability is remotely exploitable, requiring no prior authentication or privileged access to trigger the bypass. Publicly available exploit code increases the risk of immediate exploitation by threat actors.\nGiven that the vendor has not responded to disclosure attempts and the product employs a continuous delivery model, users are currently exposed without an official security patch.\nSuccessful exploitation permits unauthorized access to student-level functionality, potentially leading to unauthorized data access, account takeover, or administrative portal interaction depending on the application structure.",
"technicalDetails": "The vulnerability is located in the loginlinkstudent.php script within the CloudClassroom-PHP-Project. The root cause is a failure to properly validate or sanitize the 'umail' argument during the authentication sequence, resulting in a logic flaw that bypasses identity verification.\nIn a standard implementation, the application is expected to verify the user identity against a secure session or token associated with the provided email address. However, in the affected versions, the application logic incorrectly trusts the 'umail' input provided by the client side without verifying the authenticity of the request or ensuring that a valid session has been established.\nThe attack flow begins when an attacker sends a crafted HTTP request to loginlinkstudent.php. By manipulating the 'umail' argument, the attacker provides an identifier that the backend application fails to validate against existing user records or session state. Because the underlying code relies on the presence of this argument rather than cryptographic proof of identity or a validated session cookie, the application logic prematurely grants access to the restricted resource or authentication context.\nThe technical implication is that the application incorrectly assumes the user is already authenticated once the 'umail' parameter is received, bypassing the login portal entirely. This indicates a significant oversight in the session management and authentication handling logic within the PHP codebase.\nThis vulnerability is classified as remote, meaning an attacker can execute this exploit over the network without requiring any local access to the server. There are no privilege requirements, as the vulnerability is intended to grant privileges that the user does not possess. The impact of the exploit is high, as it grants unauthorized access to student features or sensitive information typically protected behind the application's login wall.\nBecause the exploit is currently public, attackers can easily automate the process of targeting instances of the CloudClassroom-PHP-Project. Post-exploitation, an attacker can perform any actions permitted by the student account, potentially leading to unauthorized modification of academic records, exposure of personal identifying information (PII), or leveraging the student-level access as a pivot point for further application-layer attacks."
}