PT-2026-35513 · Codeastro · Online Classroom

Wangchaoxing

·

Published

2026-04-27

·

Updated

2026-04-27

·

CVE-2026-7148

CVSS v2.0

6.5

Medium

AV:N/AC:L/Au:S/C:P/I:P/A:P
A flaw has been found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-7148

Affected Products

Online Classroom