CVE-2026-2058

HIGH

mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2026-2058. PoCs published by XiaomingX, carlosalbertotuma.

AI-analyzed exploit summary The repository contains a functional SQL injection exploit for CVE-2026-2058 in CloudClassroom PHP Project v1.0, leveraging error-based injection via the 'squeryx' POST parameter to extract database information.

Description

A flaw has been found in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3fb95b66e7be. This impacts an unknown function of the file /postquerypublic.php of the component Post Query Details Page. This manipulation of the argument gnamex causes sql injection. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

Exploits (2)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-2058

The repository contains a functional SQL injection exploit for CVE-2026-2058 in CloudClassroom PHP Project v1.0, leveraging error-based injection via the 'squeryx' POST parameter to extract database information.

Classification
Working Poc 95%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: CloudClassroom PHP Project v1.0
No auth needed
Prerequisites: access to the /postquerypublic endpoint
devstral-2 · analyzed Mar 13, 2026 Full analysis →
nomisec WORKING POC
by carlosalbertotuma · poc
https://github.com/carlosalbertotuma/CVE-2026-2058-PoC

This repository contains a functional SQL injection exploit for CVE-2026-2058 in CloudClassroom PHP Project 1.0, targeting the 'squeryx' POST parameter. The exploit automates database enumeration and data extraction using error-based SQL injection techniques.

Classification
Working Poc 100%
Attack Type
Sqli
Complexity
Moderate
Reliability
Reliable
Target: CloudClassroom PHP Project 1.0
No auth needed
Prerequisites: target with vulnerable CloudClassroom installation · network access to the target
devstral-2 · analyzed Mar 12, 2026 Full analysis →

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry technical-description
https://vuldb.com/?id.344618
Permissions Required, VDB Entry signature permissions-required
https://vuldb.com/?ctiid.344618
Exploit, Third Party Advisory, VDB Entry third-party-advisory
https://vuldb.com/?submit.744236

Scores

CVSS v3 7.3
EPSS 0.0047
EPSS Percentile 36.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-74 CWE-89
Status published
Products (1)
vishalmathur/cloudclassroom-php-project 1.0
Published Feb 06, 2026
Tracked Since Feb 18, 2026