Impact
An unknown functionality in the loginlinkadmin.php script of CodeAstro Online Classroom allows a remote attacker to manipulate the 'aid' parameter, resulting in a SQL injection vulnerability that could be used to execute arbitrary SQL statements against the application's database.
Affected Systems
CodeAstro Online Classroom version 1.0 contains the vulnerable loginlinkadmin.php file; all installations that have not applied the vendor’s fix for this version are affected.
Risk and Exploitability
The CVSS score of 6.9 denotes moderate severity. The EPSS score is less than 1%, indicating a low likelihood of widespread exploitation, and the vulnerability is not listed in the CISA KEV catalog. The flaw can be triggered remotely via crafted requests to the loginlinkadmin.php endpoint, and a publicly disclosed exploit may be used to retrieve or modify database contents.
OpenCVE Enrichment