Junglewise Threat Intelligence

CVE-2026-11471: SourceCodester Class and Exam Timetabling System SQL injection in index2.php

CVE-2026-11471 · Severity: high · CVSS 7.3 · Published 2026-06-08

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

The Class and Exam Timetabling System, a web application used for managing academic schedules, contains a security vulnerability in its login process. An attacker can exploit this flaw to bypass security controls and gain unauthorized access to the underlying database. This could lead to the theft of sensitive information, modification of academic records, or disruption of the scheduling service.

Technical details

A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the '/index2.php' component. The root cause is the improper neutralization of special elements in the 'password' POST parameter, which is used directly in SQL queries without adequate validation or prepared statements. A remote, unauthenticated attacker can exploit this by sending specially crafted malicious SQL queries to perform boolean-based blind, error-based, or time-based blind attacks. Successful exploitation allows for unauthorized database access, data exfiltration, and potential administrative takeover. A public exploit (PoC) has been disclosed.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-05-20: disclosed: Vulnerability details and PoC shared on GitHub
  • 2026-06-08: advisory: NVD/VulDB advisory published

References

Related threats