Executive brief
CloudClassroom-PHP-Project is a web application used for classroom management. An attacker can remotely inject SQL commands through the editid parameter in updateresultdetails.php, potentially accessing, modifying, or deleting sensitive student and classroom data in the underlying database.
Technical details
The vulnerability is an unauthenticated SQL injection in the updateresultdetails.php file, where the editid parameter is passed directly into an SQL query without proper sanitization. The attack is network-accessible and requires no authentication or user interaction. A successful exploit grants the attacker arbitrary database read and write access.
Affected products
- mathurvishal CloudClassroom-PHP-Project up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be
Timeline
- 2026-09-28: disclosed: Vulnerability publicly disclosed
- 2026-09-28: advisory: CVE-2026-101013 assigned