← Back to overview

A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw resides in the mysqli_query function within the file /admin/modal_add_course1.php, where manipulation of the 'course' argument enables SQL injection attacks. The vulnerability can be exploited remotely without requiring physical access to the target system. A public exploit has already been published, increasing the risk of active exploitation. The issue is tracked under CVE-2026-86221 and has been reported via VulDB and GitHub. Affected users should apply patches or mitigations immediately. The attack surface is limited to the administrative interface of the application. No authentication bypass details were specified, but remote exploitability significantly raises the severity. This type of vulnerability can lead to unauthorized database access, data exfiltration, or full system compromise.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-86221

Categories

  • Database & Storage
  • Web Technologies