A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way.
PUBLISHED5.2ApplicationCWE-89CWE-74
mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
Problem type
Affected products
mathurvishal
CloudClassroom-PHP-Project
5dadec098bfbbf3300d60c3494db3fb95b66e7be - AFFECTED
References
VDB-410596 | mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection
https://vuldb.com/vuln/410596
VDB-410596 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/410596/cti
CVE-2026-100739 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-100739
Submit #914584 | https://github.com/mathurvishal/CloudClassroom-PHP-Project CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be SQL Injection
https://vuldb.com/submit/914584
github.com
https://github.com/vinniboy021-blip/Advisory/blob/main/viewresult-sqli.md
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-100739Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-100739",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-09-26T22:00:14.688Z",
"dateReserved": "2026-09-26T06:19:41.956Z",
"datePublished": "2026-09-26T22:00:14.688Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-09-26T22:00:14.688Z"
},
"title": "mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file viewresult.php. Performing a manipulation of the argument seno results in sql injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. This product follows a rolling release approach for continuous delivery, so version details for affected or updated releases are not provided. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"affected": [
{
"vendor": "mathurvishal",
"product": "CloudClassroom-PHP-Project",
"cpes": [
"cpe:2.3:a:mathurvishal:cloudclassroom-php-project:*:*:*:*:*:*:*:*"
],
"versions": [
{
"version": "5dadec098bfbbf3300d60c3494db3fb95b66e7be",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "SQL Injection",
"cweId": "CWE-89",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Injection",
"cweId": "CWE-74",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/410596",
"name": "VDB-410596 | mathurvishal CloudClassroom-PHP-Project viewresult.php sql injection",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/410596/cti",
"name": "VDB-410596 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-100739",
"name": "CVE-2026-100739 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/914584",
"name": "Submit #914584 | https://github.com/mathurvishal/CloudClassroom-PHP-Project CloudClassroom-PHP-Project 5dadec098bfbbf3300d60c3494db3fb95b66e7be SQL Injection",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://github.com/vinniboy021-blip/Advisory/blob/main/viewresult-sqli.md",
"tags": [
"exploit"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"baseScore": 7.3,
"baseSeverity": "HIGH"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"baseScore": 7.5
}
}
],
"timeline": [
{
"time": "2026-09-26T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-09-26T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-09-26T08:24:47.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "vinniboy021 (VulDB User)",
"type": "reporter"
},
{
"lang": "en",
"value": "VulDB CNA Team",
"type": "coordinator"
}
]
}
}
}