Cross Site Scripting Vulnerability in mathurvishal CloudClassroom-PHP-Project
CVE-2026-100313

5.3MEDIUM

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-100313?

A cross site scripting vulnerability has been identified in the mathurvishal CloudClassroom-PHP-Project, affecting its updatequery.php file. By manipulating the argument 'queryx', an attacker can execute malicious scripts remotely, exposing users to potential exploits. The vendor has not responded to disclosures regarding this issue, raising concerns about timely remediation. Continuous delivery practices have made version tracking challenging, compounding the risk for users still operating on affected versions.

Affected Version(s)

CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vinniboy021 (VulDB User)
VulDB CNA Team
.