Executive brief
CloudClassroom-PHP-Project is a web-based classroom management application. An attacker can inject SQL commands through the makeid parameter in makeresult.php to extract, modify, or delete sensitive data from the application's database without authentication.
Technical details
SQL injection vulnerability in the makeresult.php file where the makeid parameter is not properly sanitized before use in database queries. The vulnerability is remotely exploitable without authentication and allows arbitrary SQL command execution. While the vendor was notified early, no patch has been provided due to the project's rolling release model.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-28: disclosed