Sceawere
Vulnerability Detail
CVE-2026-100877UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Cross-Site Scripting in CloudClassroom-PHP-Project
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 11h ago
- Vendor
- mathurvishal
- Product
- CloudClassroom-PHP-Project
- Attack Type
- Cross Site Scripting
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
A vulnerability was determined in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected by this vulnerability is an unknown functionality of the file registrationform.php. Executing a manipulation of the argument FName/LName/Addrs can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. This product implements a rolling release for ongoing delivery, which means version information for affected or updated releases is unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-09-27T21:17:00.923Z",
"pubdate": "2026-09-27T21:17:00.923Z",
"executiveSummary": "The mathurvishal CloudClassroom-PHP-Project contains a Cross-Site Scripting (XSS) vulnerability located within the registrationform.php file.\nThis vulnerability stems from improper neutralization of user-supplied input when processing registration parameters, specifically the FName, LName, and Addrs arguments.\nA remote, unauthenticated attacker can exploit this flaw by injecting malicious JavaScript payloads into these fields. When the application reflects this input back to a user's browser, the payload executes within the context of the victim's session.\nSuccessful exploitation allows for arbitrary code execution within the user's browser, potentially leading to session hijacking, unauthorized actions on behalf of the user, and the theft of sensitive session tokens or data.\nThe product utilizes a rolling release model, and all versions up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be are considered affected.\nGiven that the vendor has not responded to disclosure attempts, the risk remains high as no official vendor-supplied patch is available, and public exploit details are accessible.",
"technicalDetails": "The vulnerability is a reflected Cross-Site Scripting (XSS) issue originating from the insecure handling of HTTP POST or GET request parameters processed by the registrationform.php file in the CloudClassroom-PHP-Project.\nThe root cause is the application's failure to perform adequate input sanitization or output encoding on the 'FName', 'LName', and 'Addrs' parameters before rendering them in the server's HTTP response. By default, the application treats these input fields as trusted content, allowing an attacker to inject arbitrary HTML or JavaScript tags.\nThe attack flow begins when an attacker crafts a malicious request containing a script-based payload (e.g., <script>alert(document.cookie)</script>) in one of the vulnerable arguments. When the server processes the registration form and displays the submitted data back to the user or an administrator—often during a confirmation page or an administrative dashboard view—the application embeds the malicious script directly into the HTML document structure.\nBecause the input is not appropriately escaped or encoded, the victim's browser interprets the injected data as executable code rather than plain text. This executes the script within the origin of the vulnerable application, granting the attacker access to the same-origin security context.\nThis exposure allows for several post-exploitation scenarios, including the exfiltration of sensitive information such as session cookies, user credentials, or CSRF tokens. Additionally, the attacker can manipulate the Document Object Model (DOM) to perform UI redressing, phish for additional information, or force the victim to perform unauthorized state-changing actions.\nThe vulnerability is remotely exploitable and does not require pre-existing authentication, as it resides within the registration functionality. The impact is significant because the application fails to enforce context-aware output encoding (such as HTML entity encoding) before reflecting user input to the client side. Without server-side validation or appropriate sanitization libraries, the application remains susceptible to any payload that can be successfully parsed by common web browsers.\nThe lack of a centralized security architecture within the project to handle character escaping at the point of rendering, combined with the rolling release delivery model, necessitates manual intervention to rectify the underlying code patterns across the codebase."
}