在 mathurvishal 的 CloudClassroom-PHP-Project 项目中发现了一个漏洞,受影响版本为 5dadec098bfbbf3300d60c3494db3fb95b66e7be 及其之前的版本。该漏洞存在于文件 中的一个未知函数中。通过对参数 进行恶意操控,可以绕过身份验证机制。此漏洞可被远程利用,且利用代码已公开,可被攻击者直接使用。由于该产品采用持续交付的滚动发布模式,因此未提供受影响版本或已修复版本的具体版本号。供应商在漏洞披露早期已收到通知,但始终未作出任何回应。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mathurvishal | CloudClassroom-PHP-Project | 5dadec098bfbbf3300d60c3494db3fb95b66e7be |
cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-100875 | 7.3 HIGH | mathurvishal CloudClassroom-PHP-Project updatedetailsfromfaculty.php sql injection |
| CVE-2026-100874 | 7.3 HIGH | mathurvishal CloudClassroom-PHP-Project addnewstudent.php sql injection |
| CVE-2026-100873 | 4.3 MEDIUM | mathurvishal CloudClassroom-PHP-Project cross-site request forgery |
| CVE-2026-100877 | 4.3 MEDIUM | mathurvishal CloudClassroom-PHP-Project registrationform.php cross site scripting |
No comments yet