Junglewise Threat Intelligence

CVE-2026-100314: mathurvishal CloudClassroom-PHP-Project SQL injection in updatedetailsfromstudent.php

CVE-2026-100314 · Severity: high · CVSS 7.3 · Published 2026-09-26

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is an educational application for managing student information. A SQL injection vulnerability in the student details update feature allows remote attackers to inject malicious database queries via a parameter called eno, potentially leading to unauthorized data access, modification, or deletion of educational records.

Technical details

A SQL injection vulnerability exists in the updatedetailsfromstudent.php file where user-supplied input in the eno parameter is not properly sanitized before being used in database queries. The vulnerability can be exploited remotely without authentication, allowing an attacker to execute arbitrary SQL commands. The vendor has not responded to early disclosure attempts.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-26: disclosed: Publicly disclosed
  • 2026-09-26: exploited: Exploit code publicly available

References

Related threats