A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the mysqli_query function within the file /admin/modal_add_product.php. An attacker can exploit this vulnerability by manipulating the 'fname' argument to execute arbitrary SQL commands. The attack can be carried out remotely without requiring physical access to the system. A public exploit has already been disclosed, increasing the risk of active exploitation. The vulnerability affects the database interaction layer of the application, potentially exposing sensitive data. This issue is tracked under CVE-2026-86224 and has been documented on NVD, VulDB, and GitHub.