CodeAstro Online Classroom version 1.0 contains a SQL injection vulnerability in the updatedetailsfromfaculty.php file parameter handler, specifically within the fname argument, that could allow an authenticated attacker to execute arbitrary SQL commands. The vulnerability has a CVSS score of 6.3 (Medium) with a network attack vector, low complexity, and no user interaction required, resulting in potential unauthorized access, modification, and disruption of confidential data. Although the exploit has been publicly disclosed, the vulnerability is not currently listed on the Known Exploited Vulnerabilities catalog and shows minimal community engagement with an EPSS score indicating it ranks lower than approximately 99.99% of CVEs in terms of exploitation likelihood. Organizations running CodeAstro Online Classroom 1.0 should prioritize patching this authentication-required remote vulnerability, though the low exploitation probability suggests it is not an immediate critical threat compared to other vulnerabilities in the threat landscape.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CodeAstro | Online Classroom | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.