CVE-2026-101013: mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely without privileges or user interaction. Exploitation involves manipulating the editid argument handled by updateresultdetails.php.
Are public exploits available?
Yes. Exploit details have been publicly disclosed, so the issue may be used by attackers.
Which releases are affected?
The affected project is identified only up to commit 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Because the product does not use versioning, affected and unaffected releases cannot be determined from the available information.
Is a vendor fix available?
The available information does not identify a fix. The vendor was contacted before disclosure but did not respond.