← Back to overview

A missing authorization vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw resides in the file /admin/session.php, where manipulation of the 'ID' argument bypasses authorization checks. The vulnerability can be exploited remotely without requiring physical access to the system. A public exploit has already been released, increasing the risk of active exploitation. The issue is tracked as CVE-2026-85512 and is listed on NVD and VulDB. Affected systems running this version of the timetabling software are at risk of unauthorized access to administrative sessions. Users are advised to apply patches or mitigations as soon as they become available.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-85512

Categories

  • Identity & Access
  • Web Technologies