Cross-Site Request Forgery in CloudClassroom-PHP-Project by mathurvishal
CVE-2026-100873

5.3MEDIUM

Key Information:

Vendor
CVE Published:
27 September 2026

What is CVE-2026-100873?

A cross-site request forgery vulnerability has been identified in CloudClassroom-PHP-Project by mathurvishal. This vulnerability arises due to an unknown function that allows attackers to perform unauthorized actions on behalf of users without their consent. As this vulnerability can be exploited remotely, it poses a significant risk to users, as the exploit code is already public. The lack of versioning for this product makes it difficult to ascertain the full scope of affected releases, and despite efforts to inform the vendor about this issue, there has been no response.

Affected Version(s)

CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vinniboy021 (VulDB User)
VulDB CNA Team
.