Junglewise Threat Intelligence

CVE-2026-100311: mathurvishal CloudClassroom-PHP-Project stored cross-site scripting in Faculty Video Management

CVE-2026-100311 · Severity: low · CVSS 3.5 · Published 2026-09-26

Technologies: Mathurvishal CloudClassroom-PHP-Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is a web-based classroom management system that allows faculty to upload and manage video content. A vulnerability in the Faculty Video Management component fails to properly sanitize user input, allowing authenticated attackers to inject malicious JavaScript code that executes when other users view the affected pages. This could enable attackers to steal session cookies, impersonate users, or deface course materials.

Technical details

The vulnerability is a stored cross-site scripting (XSS) flaw in managevideos2.php, affecting the Faculty Video Management component. User-controlled input from the V_Title, V_Url, and V_Remarks parameters is stored in the database and rendered to the browser without proper HTML encoding or sanitization. An authenticated attacker can inject arbitrary JavaScript by breaking out of the textarea context (e.g., via </textarea><script>alert(1)</script>), which persists in the database and executes in the browsers of all users who view the affected page. The vulnerability requires authentication but allows session hijacking, account takeover, and defacement. The vendor uses a rolling release system and has not responded to disclosure attempts.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-26: disclosed: CVE-2026-100311 published
  • 2026-09-26: other: Exploit code publicly available on GitHub

References