A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to...
zetlyn/cve-ghsa vulnerability ghsa GHSA-hhpf-rfcr-8fx8 cve CVE-2026-100312 known 2026-09-26
https://github.com/advisories/GHSA-hhpf-rfcr-8fx8
Properties
| cvss | 6.3receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100312",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.",
"epss": {
"percentage": 0.00192,
"percentile": 0.07986
},
"ghsa_id": "GHSA-hhpf-rfcr-8fx8",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-hhpf-rfcr-8fx8"
},
{
"type": "CVE",
"value": "CVE-2026-100312"
}
],
"nvd_published_at": "2026-09-26T09:16:37Z",
"published_at": "2026-09-26T09:30:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100312",
"https://github.com/JaconiasDev/Advisory-CloundClassroom-PHP-Project-1.0",
"https://vuldb.com/cve/CVE-2026-100312",
"https://vuldb.com/submit/914575",
"https://vuldb.com/vuln/410440",
"https://vuldb.com/vuln/410440/cti",
"https://github.com/advisories/GHSA-hhpf-rfcr-8fx8"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to...",
"type": "unreviewed",
"updated_at": "2026-09-26T09:30:26Z",
"url": "https://api.github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"vulnerabilities": [],
"withdrawn_at": null
} |
|---|---|
| cwe | CWE-74receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100312",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.",
"epss": {
"percentage": 0.00192,
"percentile": 0.07986
},
"ghsa_id": "GHSA-hhpf-rfcr-8fx8",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-hhpf-rfcr-8fx8"
},
{
"type": "CVE",
"value": "CVE-2026-100312"
}
],
"nvd_published_at": "2026-09-26T09:16:37Z",
"published_at": "2026-09-26T09:30:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100312",
"https://github.com/JaconiasDev/Advisory-CloundClassroom-PHP-Project-1.0",
"https://vuldb.com/cve/CVE-2026-100312",
"https://vuldb.com/submit/914575",
"https://vuldb.com/vuln/410440",
"https://vuldb.com/vuln/410440/cti",
"https://github.com/advisories/GHSA-hhpf-rfcr-8fx8"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to...",
"type": "unreviewed",
"updated_at": "2026-09-26T09:30:26Z",
"url": "https://api.github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"vulnerabilities": [],
"withdrawn_at": null
} |
| severity | low Below 4.0. receipt
What the source handed over{
"credits": [],
"cve_id": "CVE-2026-100312",
"cvss": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_severities": {
"cvss_v3": {
"score": 6.3,
"vector_string": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"
},
"cvss_v4": {
"score": 2.1,
"vector_string": "CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
}
},
"cwes": [
{
"cwe_id": "CWE-74",
"name": "Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')"
}
],
"description": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.",
"epss": {
"percentage": 0.00192,
"percentile": 0.07986
},
"ghsa_id": "GHSA-hhpf-rfcr-8fx8",
"github_reviewed_at": null,
"html_url": "https://github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"identifiers": [
{
"type": "GHSA",
"value": "GHSA-hhpf-rfcr-8fx8"
},
{
"type": "CVE",
"value": "CVE-2026-100312"
}
],
"nvd_published_at": "2026-09-26T09:16:37Z",
"published_at": "2026-09-26T09:30:20Z",
"references": [
"https://nvd.nist.gov/vuln/detail/CVE-2026-100312",
"https://github.com/JaconiasDev/Advisory-CloundClassroom-PHP-Project-1.0",
"https://vuldb.com/cve/CVE-2026-100312",
"https://vuldb.com/submit/914575",
"https://vuldb.com/vuln/410440",
"https://vuldb.com/vuln/410440/cti",
"https://github.com/advisories/GHSA-hhpf-rfcr-8fx8"
],
"repository_advisory_url": null,
"severity": "low",
"source_code_location": "",
"summary": "A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to...",
"type": "unreviewed",
"updated_at": "2026-09-26T09:30:26Z",
"url": "https://api.github.com/advisories/GHSA-hhpf-rfcr-8fx8",
"vulnerabilities": [],
"withdrawn_at": null
} |
Text
A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to...
A security flaw has been discovered in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function of the file /updateguest.php. Performing a manipulation of the argument gname/editassid results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The vendor was contacted early about this disclosure but did not respond in any way.