CVE-2026-7148: CodeAstro Online Classroom addnewfaculty sql injection
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-7148?
CVE-2026-7148 has been classified as a high-severity SQL injection vulnerability.
How does CVE-2026-7148 affect CodeAstro Online Classroom?
CVE-2026-7148 affects the addnewfaculty functionality, allowing attackers to execute SQL injection attacks via the fname parameter.
How do I fix CVE-2026-7148?
To fix CVE-2026-7148, it's recommended to sanitize and validate all inputs in the addnewfaculty file.
Can CVE-2026-7148 be exploited remotely?
Yes, CVE-2026-7148 can be exploited remotely, allowing attackers to manipulate the fname argument.
Which version of CodeAstro Online Classroom is affected by CVE-2026-7148?
CVE-2026-7148 specifically affects CodeAstro Online Classroom version 1.0.