SQL Injection Vulnerability in mathurvishal CloudClassroom-PHP-Project
CVE-2026-101012

6.9MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101012?

A vulnerability exists in the mathurvishal CloudClassroom-PHP-Project's makeresult.php file, which allows remote attackers to exploit SQL injection through manipulation of the makeid argument. This weakness may allow unauthorized data access or manipulation, raising the potential for further attacks. As the product employs continuous delivery with rolling releases, specific version information for mitigation is not available. Despite early notification to the vendor, there has been no response regarding this issue.

Affected Version(s)

CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vinniboy021 (VulDB User)
VulDB CNA Team
.