CVE-2026-5580: CodeAstro Online Classroom Parameter addvideos.php sql injection
A vulnerability was identified in CodeAstro Online Classroom 1.0. Impacted is an unknown function of the file /OnlineClassroom/addvideos.php of the component Parameter Handler. The manipulation of the argument videotitle leads to sql injection. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5580?
CVE-2026-5580 has a high severity rating due to its potential for SQL injection exploits.
How do I fix CVE-2026-5580?
To fix CVE-2026-5580, update CodeAstro Online Classroom to the latest version or implement input validation and parameterized queries in the addvideos.php file.
Who is affected by CVE-2026-5580?
CVE-2026-5580 affects users of CodeAstro Online Classroom version 1.0.
What type of attack does CVE-2026-5580 enable?
CVE-2026-5580 enables SQL injection attacks, allowing unauthorized access to the database.
When was CVE-2026-5580 reported?
CVE-2026-5580 was reported in 2026, highlighting a significant security vulnerability.