A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the mysqli_query function within the file /admin/modal_add_course.php, where manipulation of the 'course' argument leads to SQL injection. The attack can be executed remotely without requiring physical access to the system. A public exploit is already available, increasing the risk of active exploitation. The vulnerability affects the administrative interface of the timetabling application. Attackers could potentially access, modify, or delete database contents. Given the public availability of the exploit and remote exploitability, this poses a significant risk to any organization using this software.