CVE-2026-101013 CloudClassroom-PHP-Project SQL注入漏洞
影响攻击者可远程注入SQL,窃取或篡改数据库数据
CloudClassroom-PHP-Project 的 updateresultdetails.php 文件在处理 editid 参数时未做充分过滤,存在 SQL 注入漏洞。该漏洞可被远程利用,且利用方式已公开披露,可能被实际攻击使用。
影响范围
受影响的是 mathurvishal/CloudClassroom-PHP-Project 项目,涉及提交版本 5dadec098bfbbf3300d60c3494db3fb95b66e7be 及之前代码。该项目未采用版本发布机制,因此无法给出明确的受影响与不受影响版本范围。
漏洞详情
漏洞类型为 SQL 注入。成因是 updateresultdetails.php 对 editid 参数未进行有效过滤或参数化处理,导致攻击者可构造恶意 SQL 语句。攻击者可远程发送特制请求,操纵数据库查询,从而读取、修改或删除数据。
利用条件与风险
利用前提是目标系统暴露该接口且可远程访问,无需认证即可尝试注入。由于利用代码已公开,实战中被扫描和攻击的风险较高。
修复建议
官方尚未发布修复版本,建议对 editid 参数使用参数化查询或严格过滤,并限制该接口的访问权限。临时缓解措施包括部署 WAF 拦截 SQL 注入特征请求,或暂时下线相关功能。
A security vulnerability has been detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. Affected is an unknown function of the file updateresultdetails.php. Such manipulation of the argument editid leads to sql injection. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.