Junglewise Threat Intelligence

CVE-2026-100315: mathurvishal CloudClassroom-PHP-Project SQL injection in mydetailsfaculty.php

CVE-2026-100315 · Severity: high · CVSS 7.3 · Published 2026-09-26

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom is a PHP-based classroom management application. A SQL injection vulnerability in the mydetailsfaculty.php file allows remote attackers to manipulate the myfid parameter and execute arbitrary SQL queries, potentially leading to unauthorized database access, data theft, or modification. The vulnerability has been publicly disclosed and no vendor response has been received.

Technical details

A SQL injection vulnerability exists in the mydetailsfaculty.php file where the myfid parameter is not properly sanitized before being used in SQL queries. The vulnerability can be exploited remotely without authentication via the myfid argument, allowing attackers to extract sensitive data or manipulate database contents. No patched version is available as the product does not use versioning.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-26: disclosed
  • other: Exploit is public and may be used

References

Related threats