Executive brief
A critical security vulnerability has been identified in Martcode Software's Delta Course Automation platform, a system used for managing educational courses. This flaw allows unauthorized individuals to manipulate the underlying database via the internet without needing a password. An attacker could use this to steal sensitive student or institutional data, modify records, or disrupt the availability of the service.
Technical details
A SQL injection vulnerability (CWE-89) exists in Martcode Software Inc. Delta Course Automation through version 04022026. The flaw stems from improper neutralization of special elements used in SQL commands, allowing an attacker to send malicious queries to the backend database. This is a network-based attack that requires no authentication or user interaction. Successful exploitation grants the attacker the ability to read, modify, or delete any data within the database, potentially leading to full system compromise. As of the disclosure date, the vendor has not responded to reports or provided a patch.
Affected products
- Martcode Software Inc. Delta Course Automation through 04022026
Timeline
- 2026-02-04: disclosed: Initial disclosure by USOM/CERT-TR
- 2026-02-04: advisory: CVE published to NVD