CVE-2026-6033: CodeAstro Online Classroom updatedetailsfromstudent.php sql injection
A vulnerability was determined in CodeAstro Online Classroom 1.0. Affected is an unknown function of the file /updatedetailsfromstudent.php?eno=146891650. Executing a manipulation of the argument fname can lead to sql injection. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6033?
CVE-2026-6033 is classified as a critical severity vulnerability due to the potential for SQL injection.
How do I fix CVE-2026-6033?
To fix CVE-2026-6033, validate and sanitize user inputs in the updatedetailsfromstudent.php file to prevent SQL injection.
What systems are affected by CVE-2026-6033?
CVE-2026-6033 affects CodeAstro Online Classroom version 1.0.
What type of vulnerability is CVE-2026-6033?
CVE-2026-6033 is an SQL injection vulnerability that arises from inadequate input validation.
Can CVE-2026-6033 be exploited remotely?
Yes, CVE-2026-6033 can be exploited remotely via manipulations to the fname argument in the URL.