high · CVSS v3 7.3 · CVSS v4 6.9 · EPSS 0.00259
CVE-2026-97885
CloudClassroom-PHP-Project is vulnerable to a remote SQL injection via the fid parameter in updatefaculty.php. The flaw allows attackers to
Overview
CloudClassroom-PHP-Project is vulnerable to a remote SQL injection via the fid parameter in updatefaculty.php. The flaw allows attackers to manipulate database queries and potentially exfiltrate or modify data. It is publicly disclosed and can be exploited without authentication.
Description
A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updatefaculty.php. This manipulation of the argument fid causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The vendor was contacted early about this disclosure but did not respond in any way.
Impact
The vulnerability compromises confidentiality by allowing attackers to read sensitive data, integrity by enabling unauthorized data modification, and availability if the database is overwhelmed. Defenders are the administrators of the CloudClassroom-PHP-Project deployment.
Remediation
Apply the latest patch or upgrade to a fixed release once available. In the meantime, enforce strict input validation and use parameterized queries for the fid parameter. Restrict database user privileges to the minimum required and monitor database logs for suspicious activity.
Risk context
Severity is high (CVSS 7.3) but EPSS is very low (0.00259), indicating a low probability of exploitation in the wild. Defenders should still prioritize patching due to the potential impact.
Affected products
- CloudClassroom-PHP-Project
Scores
- Severity
- high
- CVSS v2
- 7.5
- CVSS v3
- 7.3
- CVSS v4
- 6.9
- EPSS
- 0.00259