Executive brief
CloudClassroom-PHP-Project is a web-based classroom management application. An authenticated attacker can exploit a SQL injection vulnerability in the guest name update feature to extract sensitive data from the database, including credentials and system information, potentially leading to full compromise of the application and its data.
Technical details
A SQL injection vulnerability exists in the updateguest.php file where the gname parameter is concatenated directly into SQL queries without sanitization or prepared statements. An authenticated attacker can send a crafted POST request to /updateguest.php with a malicious gname payload to execute arbitrary SQL commands, enabling database enumeration, credential extraction, and data exfiltration. No official fix is currently available from the vendor.
Affected products
- mathurvishal CloudClassroom-PHP-Project 1.0 and prior
Timeline
- 2026-03-08: disclosed
- 2026-09-28: advisory