Junglewise Threat Intelligence

CVE-2026-100875: CloudClassroom-PHP-Project SQL injection in updatedetailsfromfaculty.php

CVE-2026-100875 · Severity: high · CVSS 7.3 · Published 2026-09-27

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is a PHP-based classroom management application. An SQL injection vulnerability in the updatedetailsfromfaculty.php file allows remote attackers to manipulate database queries via the myfid parameter, potentially exposing or modifying sensitive academic records and student information. The vulnerability can be exploited without authentication and the exploit code has been publicly disclosed.

Technical details

SQL injection in the updatedetailsfromfaculty.php file allows manipulation of the myfid parameter to inject arbitrary SQL commands. The vulnerability is remotely exploitable without authentication, enabling database enumeration, data extraction, and potential data modification. Proof-of-concept code has been publicly released on GitHub.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-27: disclosed: SQL injection advisory published on GitHub

References

Related threats