Sceawere

Vulnerability Detail

CVE-2026-100894UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in CloudClassroom-PHP-Project

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
6h ago
Vendor
mathurvishal
Product
CloudClassroom-PHP-Project
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This issue affects some unknown processing of the file updateguest.php. The manipulation of the argument gname leads to sql injection. The attack may be initiated remotely. The exploit is publicly available and might be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-09-28T02:17:19.260Z",
  "pubdate": "2026-09-28T02:17:19.260Z",
  "executiveSummary": "A critical SQL injection vulnerability exists in the mathurvishal CloudClassroom-PHP-Project, specifically within the updateguest.php file.\nThe vulnerability arises from improper sanitization of the 'gname' argument, allowing remote, unauthenticated attackers to inject malicious SQL queries.\nSuccessful exploitation facilitates unauthorized interaction with the backend database, potentially leading to data exfiltration, modification, or deletion.\nThe product utilizes a rolling release model, complicating version tracking, though versions up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be are confirmed affected.\nGiven the availability of public exploit code, the risk of exploitation is high, and the vendor has not provided a resolution.\nOrganizations deploying this project are at significant risk of database compromise and loss of confidentiality, integrity, and availability.",
  "technicalDetails": "The vulnerability resides in the updateguest.php script, which fails to adequately sanitize user-supplied input provided via the 'gname' parameter before incorporating it into a database query.\nThe root cause is a lack of prepared statements or parameterized queries when handling user input. Instead, the application likely concatenates the raw 'gname' input directly into an SQL command string, allowing an attacker to escape the intended query structure.\nThe attack flow begins with an adversary sending a crafted HTTP request to updateguest.php, where the 'gname' parameter is substituted with malicious SQL syntax (e.g., `' OR 1=1 --`). Because the application executes this query blindly, the database interprets the injected commands as part of the logic rather than literal string data.\nThe impact of this vulnerability is severe, as it grants an attacker the ability to bypass application-level authentication, perform unauthorized data queries (UNION-based SQL injection), or potentially perform administrative operations on the database server.\nSince the vulnerability is triggered via a standard HTTP request, it is network-accessible and does not require prior authentication, significantly broadening the attack surface.\nPost-exploitation activities could involve the systematic dumping of user tables, configuration leakage, or the modification of application data to facilitate further attacks like privilege escalation.\nThe absence of vendor response implies that no official patch is available to remediate this specific defect in the codebase, leaving the underlying logic flaw exposed for all instances running affected code versions up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be."
}
CVE-2026-100894: SQL Injection in CloudClassroom-PHP-Project (MEDIUM Severity, CVSS: 6.3) | Sceawere