← Terug naar overzicht

A SQL injection vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability exists in the mysqli_query function within the file /admin/modal_add_course2.php. An attacker can manipulate the 'course' argument to perform SQL injection attacks. The attack can be launched remotely without requiring physical access. A public exploit has been disclosed, making this vulnerability actively exploitable. The affected product is a web-based academic scheduling system. No authentication bypass details are specified, but remote exploitation increases the risk significantly. The vulnerability has been assigned CVE-2026-86222 and is tracked by NVD and VulDB.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Related CVE's

  • CVE-2026-86222

Categories

  • Database & Storage
  • Web Technologies