← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the mysqli_query function within the file /admin/modal_add_room.php. An attacker can manipulate the room_name argument to inject malicious SQL code. The attack can be executed remotely without requiring physical access to the target system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects the database layer of the application, potentially allowing unauthorized data access or manipulation. Users of this system are advised to apply patches or mitigations immediately given the public availability of the exploit.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-86225

Categories

  • Database & Storage
  • Web Technologies