Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-5580

25
FAUCET Score

CVE-2026-5580 is a SQL injection vulnerability affecting CodeAstro Online Classroom version 1.0, specifically in the /OnlineClassroom/addvideos.php file's Parameter Handler component. An attacker can manipulate the videotitle argument to execute arbitrary SQL commands against the underlying database. The vulnerability requires remote access and valid user credentials to exploit, making it a network-based attack with low complexity. The vulnerability carries a CVSS 3.1 score of 6.3 (Medium severity), indicating moderate risk with potential impacts to confidentiality, integrity, and availability of the system. The attack requires low privilege authentication but no user interaction. With an EPSS score of 0.00011 and a FAUCET Risk Score of 44.0 out of 100, this vulnerability represents a relatively low statistical likelihood of exploitation compared to the broader threat landscape. Exploit code for this vulnerability is publicly available, which increases operational risk. However, the vulnerability is not currently tracked on CISA's Known Exploited Vulnerabilities (KEV) catalog and is not listed on active hot lists, suggesting no widespread active exploitation at this time. Organizations running CodeAstro Online Classroom 1.0 should prioritize applying patches or implementing access controls to mitigate this authenticated SQL injection risk.

Impacted Technologies

VendorProductVersion(s)CPE
CodeAstroOnline Classroom
1.0CNA affected

CVSS Data

CVSS version used by this source: 4.0

2.1LOW

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Attack Vector
NETWORK
Attack Complexity
LOW
Attack Requirements
NONE
Privileges Required
LOW
User Interaction
NONE
VS Confidentiality
LOW
VS Integrity
LOW
VS Availability
LOW
SS Confidentiality
NONE
SS Integrity
NONE
SS Availability
NONE
Exploit Maturity
PROOF_OF_CONCEPT
CvssVersion
4.0

Exploit Intelligence

EPSS Score
0.26%
Probability of exploitation in next 30 days
EPSS Percentile
17.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0026 is in the 21st percentile among its peer group of 21,977 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Remediation records are not available for this CVE.

References

codeastro.com
github.com / zgr0508/cve/issues/3
vuldb.com / submit/783753
vuldb.com / vuln/355350
vuldb.com / vuln/355350/cti