Junglewise Threat Intelligence

CVE-2026-5580: CodeAstro Online Classroom SQL injection in addvideos.php

CVE-2026-5580 · Severity: medium · CVSS 6.3 · Published 2026-04-05

Technologies: CodeAstro Online Classroom. Vendors: CodeAstro.

Executive brief

A security vulnerability exists in CodeAstro Online Classroom, a web-based platform for managing educational content. An attacker can exploit this flaw to interfere with the application's database, potentially leading to the unauthorized viewing, modification, or deletion of sensitive classroom data. This could result in a loss of data integrity or the exposure of private student and course information.

Technical details

A SQL injection vulnerability exists in CodeAstro Online Classroom 1.0 within the 'Parameter Handler' component. The root cause is the improper neutralization of special elements in the 'videotitle' POST parameter used in the /OnlineClassroom/addvideos.php script. An attacker with low-level privileges can submit a crafted 'videotitle' argument containing malicious SQL syntax, such as time-based blind payloads (e.g., using SLEEP functions). Successful exploitation allows for unauthorized database access, data tampering, and potential leakage of sensitive information. A public proof-of-concept (PoC) exploit using sqlmap has been disclosed.

Affected products

  • CodeAstro Online Classroom 1.0

Timeline

  • 2026-03-20: disclosed: Initial disclosure on GitHub issues
  • 2026-04-05: advisory: CVE published and VulDB entry created

References

Related threats