Executive brief
CloudClassroom-PHP-Project is a PHP-based classroom management application. An SQL injection vulnerability in the updatedetailsfromfaculty.php file allows remote attackers to manipulate database queries via the myfid parameter, potentially exposing or modifying sensitive academic records and student information. The vulnerability can be exploited without authentication and the exploit code has been publicly disclosed.
Technical details
SQL injection in the updatedetailsfromfaculty.php file allows manipulation of the myfid parameter to inject arbitrary SQL commands. The vulnerability is remotely exploitable without authentication, enabling database enumeration, data extraction, and potential data modification. Proof-of-concept code has been publicly released on GitHub.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-27: disclosed: SQL injection advisory published on GitHub