Junglewise Threat Intelligence

CVE-2026-100313: CloudClassroom-PHP-Project stored cross-site scripting in updatequery.php

CVE-2026-100313 · Severity: medium · CVSS 4.3 · Published 2026-09-26

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

A PHP-based classroom management application contains a stored cross-site scripting (XSS) vulnerability in its query handling code. An attacker can inject malicious scripts through the queryx parameter that execute in other users' browsers, potentially allowing session hijacking, credential theft, or defacement of the application. The vulnerability can be exploited remotely and a working exploit has been publicly disclosed.

Technical details

Stored XSS vulnerability in updatequery.php allows manipulation of the queryx parameter to inject unsanitized input reflected to other users. The attack requires network access to the web application and successful execution depends on the victim viewing a page containing the injected payload. An attacker gains the ability to execute arbitrary JavaScript in the context of other users' sessions.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-26: disclosed

References

Related threats