CVE-2026-5578: CodeAstro Online Classroom Parameter addassessment.php sql injection
A vulnerability was found in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /OnlineClassroom/addassessment.php of the component Parameter Handler. Performing a manipulation of the argument deleteid results in sql injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5578?
CVE-2026-5578 is classified as a medium severity SQL injection vulnerability.
How do I fix CVE-2026-5578?
To fix CVE-2026-5578, ensure that proper input validation and parameterized queries are implemented in the addassessment.php file.
What components are affected by CVE-2026-5578?
CVE-2026-5578 affects the Parameter Handler component in CodeAstro Online Classroom version 1.0.
Can CVE-2026-5578 be exploited remotely?
Yes, CVE-2026-5578 can be exploited remotely if an attacker manipulates the arguments sent to the vulnerable addassessment.php file.
What kind of attacks can CVE-2026-5578 enable?
CVE-2026-5578 can enable an attacker to perform SQL injection attacks, leading to unauthorized access to the database.