SQL Injection Vulnerability in CloudClassroom-PHP-Project by mathurvishal
CVE-2026-101013

6.9MEDIUM

Key Information:

Vendor
CVE Published:
28 September 2026

What is CVE-2026-101013?

A critical security vulnerability has been found in the mathurvishal CloudClassroom-PHP-Project affecting the updateresultdetails.php file. This vulnerability arises from improper handling of the 'editid' argument, leading to a SQL injection that can be exploited remotely. The potential exploit is publicly known, and the lack of versioning in the product complicates the identification of specific affected or unaffected releases. Despite early notifications to the vendor regarding this security risk, there has been no response to date.

Affected Version(s)

CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

vinniboy021 (VulDB User)
VulDB CNA Team
.