CVE-2026-5580 is a SQL injection vulnerability affecting CodeAstro Online Classroom version 1.0, specifically in the /OnlineClassroom/addvideos.php file's Parameter Handler component. An attacker can manipulate the videotitle argument to execute arbitrary SQL commands against the underlying database. The vulnerability requires remote access and valid user credentials to exploit, making it a network-based attack with low complexity. The vulnerability carries a CVSS 3.1 score of 6.3 (Medium severity), indicating moderate risk with potential impacts to confidentiality, integrity, and availability of the system. The attack requires low privilege authentication but no user interaction. With an EPSS score of 0.00011 and a FAUCET Risk Score of 44.0 out of 100, this vulnerability represents a relatively low statistical likelihood of exploitation compared to the broader threat landscape. Exploit code for this vulnerability is publicly available, which increases operational risk. However, the vulnerability is not currently tracked on CISA's Known Exploited Vulnerabilities (KEV) catalog and is not listed on active hot lists, suggesting no widespread active exploitation at this time. Organizations running CodeAstro Online Classroom 1.0 should prioritize applying patches or implementing access controls to mitigate this authenticated SQL injection risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| CodeAstro | Online Classroom | 1.0CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.