← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the mysqli_query function within the file /admin/modal_add_coursea.php, where manipulation of the 'course' argument allows SQL injection attacks. The vulnerability is remotely exploitable, meaning attackers do not require local access to the target system. A public exploit has already been released, increasing the risk of active exploitation in the wild. The vulnerability is tracked as CVE-2026-86223 and has been assigned a high criticality rating. Organizations using this software should apply mitigations or patches immediately to prevent unauthorized database access or data exfiltration.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-86223

Categories

  • Database & Storage
  • Web Technologies
  • Zero-Day Vulnerabilities