Junglewise Threat Intelligence

CVE-2026-100877: CloudClassroom-PHP-Project stored XSS in registration form

CVE-2026-100877 · Severity: medium · CVSS 4.3 · Published 2026-09-27

Technologies: Mathurvishal CloudClassroom PHP Project. Vendors: Mathurvishal.

Executive brief

CloudClassroom-PHP-Project is a student management application with a public registration form. An unauthenticated attacker can inject malicious scripts into student registration fields (first name, last name, address) that are executed when other users view student details, enabling account takeover, session hijacking, or credential theft.

Technical details

Stored cross-site scripting vulnerability in registrationform.php where user-supplied input parameters (FName, LName, Addrs) are stored without sanitization and reflected in studentdetails.php without proper encoding. An unauthenticated attacker can inject JavaScript payloads via self-registration that execute in the browsers of users viewing student profiles. The vulnerability requires no authentication or user interaction beyond normal application use.

Affected products

  • mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be

Timeline

  • 2026-09-27: disclosed
  • 2026-09-27: advisory: Public advisory released; vendor did not respond to early disclosure notification

References

Related threats