Sceawere

Vulnerability Detail

CVE-2026-101013UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

SQL Injection in CloudClassroom-PHP-Project

Vulnerability Metadata

Severity
High
Score / CVSS
7.3
Creation Date
4h ago
Vendor
mathurvishal
Product
CloudClassroom-PHP-Project
Attack Type
SQL Injection
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.3",
  "pubDate": "2026-09-28T08:16:37.313Z",
  "pubdate": "2026-09-28T08:16:37.313Z",
  "executiveSummary": "The CloudClassroom-PHP-Project contains a critical SQL injection vulnerability within the updateresultdetails.php file.\nThis vulnerability is classified as an improper neutralization of special elements used in an SQL command (SQL Injection).\nIt allows a remote, unauthenticated attacker to manipulate the 'editid' argument, leading to unauthorized database queries.\nThe security risk is high, as the vulnerability facilitates direct interaction with the backend database, potentially leading to data exfiltration, unauthorized modification, or complete compromise of the database contents.\nThe vulnerability is currently public, and given the lack of vendor response or available patches, the product remains indefinitely exposed to exploitation attempts.\nAttackers can leverage this vulnerability to gain unauthorized access to sensitive application data or internal system information by injecting malicious SQL statements through the affected parameter.",
  "technicalDetails": "The vulnerability resides in updateresultdetails.php within the CloudClassroom-PHP-Project, specifically impacting how the application handles the 'editid' HTTP GET or POST parameter.\nThe root cause is the improper sanitization and validation of the 'editid' argument before it is concatenated directly into a database query string.\nBecause the application fails to utilize prepared statements or parameterized queries, the input is treated as executable code by the underlying database management system.\nExploitation is achieved by supplying a crafted 'editid' value containing SQL syntax elements, such as single quotes, comment sequences (e.g., --, #), or UNION SELECT statements.\nA typical attack flow involves an attacker identifying the endpoint and submitting a manipulated request, for instance: updateresultdetails.php?editid=1' OR '1'='1. The database processes this modified query, which alters the original logic of the statement.\nThe vulnerability is remotely exploitable, allowing an attacker to craft requests from any location with network access to the application server.\nSince the affected component does not implement robust authentication or access control checks for this specific operation, the attack can be executed by unauthorized remote users.\nThe impact of a successful exploitation is severe; attackers can bypass authentication mechanisms, disclose sensitive information contained within the database, or modify, append, or delete records within the database tables.\nAs the codebase lacks versioning, all instances up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be are considered vulnerable.\nThe lack of vendor intervention means that no official security patches or updates are available to resolve the underlying flaw in the source code."
}
CVE-2026-101013: SQL Injection in CloudClassroom-PHP-Project (HIGH Severity, CVSS: 7.3) | Sceawere