SQL Injection Vulnerability in CodeAstro Online Classroom by CodeAstro
CVE-2026-16765
Key Information:
- Vendor
Codeastro
- Status
- Vendor
- CVE Published:
- 23 July 2026
Badges
What is CVE-2026-16765?
A SQL injection vulnerability has been identified within the CodeAstro Online Classroom application at the '/OnlineClassroom/loginlinkadmin.php' endpoint. By manipulating the 'aid' parameter, an attacker may execute arbitrary SQL commands, potentially leading to unauthorized access to the database. This vulnerability is exploitable remotely, and details have been made publicly available, increasing the risk of exploitation. It is crucial for users of the affected version to take remediation steps to safeguard their systems.
Affected Version(s)
Online Classroom 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
