Sceawere
Vulnerability Detail
CVE-2026-101012UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
SQL Injection in CloudClassroom-PHP-Project
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.3
- Creation Date
- 4h ago
- Vendor
- mathurvishal
- Product
- CloudClassroom-PHP-Project
- Attack Type
- SQL Injection
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Attack Complexity
- LOW
Narrative and Response
Description
A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file makeresult.php. This manipulation of the argument makeid causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.3",
"pubDate": "2026-09-28T08:16:37.147Z",
"pubdate": "2026-09-28T08:16:37.147Z",
"executiveSummary": "The mathurvishal CloudClassroom-PHP-Project contains a critical SQL injection vulnerability within the makeresult.php file.\nThis vulnerability stems from improper neutralization of special elements used in an SQL command, specifically within the 'makeid' argument.\nA remote, unauthenticated attacker can exploit this flaw to manipulate database queries, potentially leading to unauthorized data access, modification, or deletion.\nGiven that the application utilizes a continuous delivery model without distinct versioning, all deployments prior to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be are considered susceptible.\nThe public availability of exploit code significantly elevates the risk, as it lowers the barrier to entry for malicious actors.\nDue to a lack of vendor responsiveness, no official patch information is available, necessitating proactive manual intervention by administrators to secure affected instances.",
"technicalDetails": "The vulnerability is identified as a classic SQL injection (SQLi) flaw localized to the makeresult.php file within the CloudClassroom-PHP-Project repository.\nThe root cause is the insecure handling of the 'makeid' parameter, which is passed directly to database queries without adequate sanitization, parameterization, or the use of prepared statements.\nThe application fails to employ rigorous input validation or context-aware encoding, allowing an attacker to inject arbitrary SQL fragments into the backend query structure.\nThe attack flow begins with the attacker crafting a malicious HTTP request targeting the makeresult.php script. By manipulating the 'makeid' GET or POST parameter, the attacker can break out of the intended SQL syntax constraints.\nFor instance, an attacker may inject UNION-based payloads to extract sensitive information from other tables within the database, or employ error-based SQLi techniques to map the database schema. Because the application processes these inputs dynamically, the injected SQL code is executed with the privileges of the database user configured for the web application.\nExploitation is feasible remotely over a network without requiring prior authentication. The impact is significant, as it can lead to full database compromise, data exfiltration, or modification of administrative records if the application user account possesses sufficient privileges.\nThe vulnerability affects the project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Given the absence of versioning, users are advised to verify their source code against this commit hash.\nPost-exploitation, an attacker could potentially gain unauthorized administrative access, manipulate educational data, or leverage the compromised database to perform further attacks against the hosting environment, depending on the server configuration and database user permissions."
}