Registrodiclasse
Pre-authentication blind SQL injection in registrodiclasse.it
Summary
A pre-authentication blind SQL injection vulnerability affected the hosted registrodiclasse.it platform. The issue was responsibly reported to Arvea on 30 June 2026 and was confirmed remediated on 5 September 2026.
To comply with the coordinated disclosure agreement, this advisory intentionally excludes payloads, extracted information, and details of any additional test endpoints.
Affected service
- Supplier: Arvea
- Service:
registrodiclasse.it - Component:
/geopcfp2/modal/modal_alunno.asp - Parameter:
idAlunno - Authentication required: No
- Weakness: Blind SQL injection (CWE-89)
- Affected: Hosted service before 5 September 2026
- Status: Remediated
Impact
An unauthenticated remote attacker could provide crafted input that altered backend database queries. Arvea confirmed through application-log analysis that testing conducted before remediation enabled the extraction of limited database metadata.
No payloads, extracted data, or extracted metadata are included in this advisory.
Remediation
Arvea reported implementing centralized validation for query-string, form, and cookie inputs, including numeric allowlisting for record identifiers. Detailed database errors are no longer returned to clients, and centralized logging was introduced for detected attack attempts.
Arvea completed verification of the remediation on 5 September 2026 and reported that subsequent traffic logs confirmed the relevant attack patterns were blocked.
Timeline
- 30 June 2026: Initial vulnerability report submitted to Arvea.
- July–August 2026: Analysis and iterative remediation.
- 5 September 2026: Remediation verification completed and written confirmation issued.
- 9 September 2026: Public advisory prepared.
Credit
Discovered and responsibly reported by “c0derpwner”.
Disclosure authorization
Arvea authorized publication of its remediation confirmation and attribution of the blind SQL injection discovery on registrodiclasse.it, provided that publication remains limited to this platform and excludes operational payloads, additional test endpoints, and extracted data or metadata. This advisory observes those conditions.
CVE
CVE ID requested; assignment pending.