Junglewise Threat Intelligence

CVE-2026-6010: CodeAstro Online Classroom SQL injection in takeassessment2.php

CVE-2026-6010 · Severity: medium · CVSS 6.3 · Published 2026-04-10

Technologies: CodeAstro Online Classroom. Vendors: CodeAstro.

Executive brief

CodeAstro Online Classroom, a web-based platform for managing educational courses and assessments, contains a security vulnerability in its assessment processing component. An attacker can exploit this flaw to interfere with the underlying database, potentially leading to the unauthorized viewing of sensitive student data or the modification of records. This could compromise the integrity of the classroom environment and lead to data leaks or service disruptions.

Technical details

A SQL injection vulnerability exists in CodeAstro Online Classroom 1.0 within the /OnlineClassroom/takeassessment2.php file. The root cause is the failure to properly sanitize or validate the 'Q1' POST parameter before using it in a SQL query. A remote attacker with low privileges (such as a student account) can provide malicious input to manipulate database queries. Successful exploitation can lead to unauthorized database access, data leakage, or tampering. Public proof-of-concept exploits using boolean-based, error-based, and time-based blind techniques have been released.

Affected products

  • CodeAstro Online Classroom 1.0

Timeline

  • 2026-04-10: disclosed: Vulnerability reported via GitHub issue and VulDB
  • 2026-04-10: advisory: CVE-2026-6010 published

References