在 mathurvishal CloudClassroom-PHP-Project(截至版本 5dadec098bfbbf3300d60c3494db3fb95b66e7be)中发现了一个漏洞。该问题影响了文件 updateguest.php 中某些未明确定义的处理逻辑。通过对参数 gname 的操作,可导致 SQL 注入攻击。此漏洞可能被远程利用。相关利用代码已公开,可能被攻击者使用。 该产品采用滚动发布模型,以持续提供更新。因此,无法提供受影响版本或已修复版本的具体版本信息。我们已在披露前尽早联系厂商,但厂商未
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| mathurvishal | CloudClassroom-PHP-Project | 5dadec098bfbbf3300d60c3494db3fb95b66e7be |
cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-101012 | 7.3 HIGH | mathurvishal CloudClassroom-PHP-Project makeresult.php sql injection |
| CVE-2026-101013 | 7.3 HIGH | mathurvishal CloudClassroom-PHP-Project updateresultdetails.php sql injection |
No comments yet