SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project
CVE-2026-100314

6.9MEDIUM

Key Information:

Vendor
CVE Published:
26 September 2026

What is CVE-2026-100314?

A significant security vulnerability exists in the mathurvishal CloudClassroom-PHP-Project that affects the updatedetailsfromstudent.php file. This vulnerability allows for SQL injection through improper handling of the argument 'eno'. Attackers can exploit this flaw remotely, potentially compromising the integrity and confidentiality of the database. The vendor has not responded to disclosures about this issue, raising concerns regarding the ongoing safety and security of the application as it employs continuous delivery with rolling releases, making it difficult to ascertain specific affected or updated versions.

Affected Version(s)

CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vinniboy021 (VulDB User)
VulDB CNA Team
.