CVE-2026-6010Disclosure

LOWCVSS 2.1 · LOW

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/takeassessment2.php?exid=14. Performing a manipulation of the argument Q1 results in sql injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

ACTIVE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 1 classified signals
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 3 mentions (2026-04-10); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-04-10: 3Mentions · 2026-04-11: 1Active Exploitation · 2026-04-10: 1Technical Details · 2026-04-10: 2Technical Details · 2026-04-11: 104-1004-11
Signal classification2 categories
Disclosure
375.0%
Active Exploitation
125.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-103
Active Exploitation1Disclosure2
2026-04-111
Disclosure1
Full discourse4 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-6010 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-6010 #CVE-2026-6010 #CVE #Medium #CyberSecurity #InfoSec https://t.co/4gHpfVsBLP

    Post summary

    A newly disclosed CVE-2026-6010 with a medium severity score (6.3) impacting unspecified products is announced, but no exploitation details or patches are provided.

    0000036
    125 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6010 A security flaw has been discovered in CodeAstro Online Classroom 1.0/2.php. Affected by this vulnerability is an unknown functionality of the file /OnlineClassroom/tak… https://www.cve.org/CVERecord?id=CVE-2026-6010

    Post summary

    CVE-2026-6010 reports a security flaw in CodeAstro Online Classroom 1.0/2.php affecting an unspecified functionality of /OnlineClassroom/tak, but provides no technical details, PoC, or mitigation information.

    00000102
    57.0K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Active Exploitation

    CVE-2026-6010 SQL Injection in CodeAstro Online Classroom 1.0 via Q1 Parameter (Exploitation Reported) https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-6010

    Post summary

    The note indicates that SQL injection is actively being exploited against CodeAstro Online Classroom 1.0 via the Q1 parameter, but no PoC, exploit code, or patch information is offered.

    0000045
    4.0K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-6010 - CodeAstro Online Classroom takeassessment2.php sql injection Intel Report: https://ift.tt/0cVSZju

    Post summary

    The tweet alerts on CVE‑2026‑6010 as a SQL injection in CodeAstro's takeassessment2.php and links to an intel report, but offers no PoC, exploit code, active exploitation evidence, or mitigation details.

    0000032
    280 followersView on X

Explore more