CVE-2026-100873
Received Received - Intake

Cross-Site Request Forgery in CloudClassroom PHP Project

Vulnerability report for CVE-2026-100873, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-27

Last updated on: 2026-09-27

Assigner: VulDB

Description

A vulnerability was detected in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. The impacted element is an unknown function. The manipulation results in cross-site request forgery. The attack can be launched remotely. The exploit is now public and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-27
Last Modified
2026-09-27
Generated
2026-09-27
AI Q&A
2026-09-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
mathurvishal cloudclassroom_php_project to 5dadec098bfbbf3300d60c3494db3fb95b66e7be (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
CWE-352 The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the mathurvishal CloudClassroom-PHP-Project. It allows attackers to trick users into performing unwanted actions on the web application without their consent. The exploit is publicly available and can be launched remotely.

Detection Guidance

This vulnerability is a Cross-Site Request Forgery (CSRF) issue in the mathurvishal CloudClassroom-PHP-Project. Detection typically involves inspecting web application traffic for unauthorized requests or unusual user actions. Check server logs for suspicious POST requests without proper CSRF tokens. Use tools like Burp Suite or OWASP ZAP to monitor for CSRF vulnerabilities.

Impact Analysis

If you use the affected CloudClassroom-PHP-Project, an attacker could perform actions on your behalf without your knowledge. This might include changing settings, submitting data, or performing other unintended actions. The impact is limited due to a low CVSS score but still poses a risk.

Compliance Impact

This CSRF vulnerability could potentially lead to unauthorized changes in user data or settings, which may violate compliance requirements under GDPR (data integrity) or HIPAA (unauthorized access). However, the low CVSS score suggests minimal impact.

Mitigation Strategies

Immediately disable or remove the mathurvishal CloudClassroom-PHP-Project from your network or system. Since the vendor did not respond and no patches are available, consider replacing it with a secure alternative. Monitor network traffic for unusual cross-site request forgery patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100873. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart