CVE-2026-7743: CodeAstro Online Classroom studentdetails sql injection
Published May 4, 2026
·Updated
A vulnerability has been found in CodeAstro Online Classroom 1.0. The impacted element is an unknown function of the file /OnlineClassroom/studentdetails. The manipulation of the argument deleteid leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Codeastro CodeAstro Online Classroom=1.0
Event History
May 4, 2026
CVE Published
via MITRE·07:15 AM
Data Sourced
via MITRE·07:15 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:16 AM
DescriptionSeverityWeakness
Oct 14, 58358
Event
via FIRST·01:50 AM
Frequently Asked Questions
1
What is the severity of CVE-2026-7743?
CVE-2026-7743 has a high severity level due to the potential for SQL injection attacks.
2
How do I fix CVE-2026-7743?
To fix CVE-2026-7743, validate and sanitize all inputs to the /OnlineClassroom/studentdetails endpoint.
3
What systems are affected by CVE-2026-7743?
CVE-2026-7743 affects CodeAstro Online Classroom version 1.0.
4
What type of vulnerability is CVE-2026-7743?
CVE-2026-7743 is classified as an SQL injection vulnerability.
5
Can CVE-2026-7743 be exploited remotely?
Yes, CVE-2026-7743 can be exploited remotely if the attacker can reach the affected web application.