A vulnerability, which was classified as critical, was found in CodeAstro Online Classroom 1.0. This affects an unknown part of the file /addnewfaculty. Executing a manipulation of the argument fname can lead to sql injection.
This vulnerability is handled as CVE-2026-7148. The attack can be executed remotely. Additionally, an exploit exists.