Executive brief
CloudClassroom-PHP-Project is a web-based classroom management application. A SQL injection vulnerability in the student addition function allows remote attackers to manipulate database queries, potentially leading to unauthorized data access, modification, or deletion of student records and other sensitive information.
Technical details
The vulnerability is a SQL injection flaw in the addnewstudent.php file that allows unauthenticated remote code execution through unsanitized user input. An attacker can craft malicious SQL queries to interact with the backend database directly. The product's rolling release model means no specific vulnerable versions are documented, though the flaw affects at least the commit up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-27: disclosed: Public disclosure via GitHub advisory