Junglewise Threat Intelligence

CVE-2026-100873: mathurvishal CloudClassroom-PHP-Project cross-site request forgery

CVE-2026-100873 · Severity: medium · CVSS 4.3 · Published 2026-09-27

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is an educational classroom management application. A cross-site request forgery vulnerability in the application allows attackers to perform unauthorized actions on behalf of authenticated users by tricking them into visiting a malicious webpage. The exploit is publicly available, increasing the risk of widespread attack.

Technical details

The vulnerability is a cross-site request forgery (CSRF) flaw in an unknown function of CloudClassroom-PHP-Project that can be exploited remotely without authentication. The vulnerable component lacks CSRF token validation, allowing attackers to forge requests and execute actions with the privileges of a logged-in user. No vendor patch is available.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-27: disclosed

References

Related threats