Junglewise Threat Intelligence

CVE-2026-100739: CloudClassroom-PHP-Project SQL injection in viewresult.php

CVE-2026-100739 · Severity: high · CVSS 7.3 · Published 2026-09-26

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is a web-based classroom management system. An attacker can remotely inject malicious SQL commands through the seno parameter in viewresult.php without authentication, allowing unauthorized access to sensitive student or classroom data stored in the application's database.

Technical details

A SQL injection vulnerability exists in viewresult.php where the seno parameter is not properly sanitized before use in database queries. The vulnerability is remotely exploitable over the network without requiring authentication. Successful exploitation allows attackers to read, modify, or delete database records and potentially execute arbitrary database operations.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-26: disclosed: Vulnerability publicly disclosed

References

Related threats