Impact
The vulnerability is a classic SQL injection in the studentlogin endpoint of CodeAstro Online Classroom 1.0. By manipulating the sid parameter, an attacker can inject arbitrary SQL commands, potentially reading, modifying, or deleting student data stored in the database. The flaw resides in a publicly accessible endpoint, enabling remote attackers to exploit it without needing authentication, and a public exploit is already available on GitHub and in vulnerability databases.
Affected Systems
CodeAstro Online Classroom 1.0 is affected. The flaw exists in the /OnlineClassroom/studentlogin endpoint, and no other product versions are currently listed as vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity level. While the EPSS score is not available, the remote nature of the attack vector and the existence of a public exploit suggest that the vulnerability presents a realistic threat. The vulnerability has not been listed in CISA KEV, but the potential for unauthorized access to sensitive student data warrants prompt action.
OpenCVE Enrichment