← Back to overview

A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /delete_subject.php file, where manipulation of the 'ID' argument allows an attacker to perform SQL injection. The attack can be initiated remotely without requiring physical access. A public exploit has already been released, increasing the risk of active exploitation. The vulnerability affects an unknown function within the identified file. No authentication bypass details are specified, but remote exploitability makes this a significant risk. The issue has been documented across multiple security databases including NVD and VulDB.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-86298

Categories

  • Database & Storage
  • Web Technologies