Junglewise Threat Intelligence

CVE-2026-11472: SourceCodester Class and Exam Timetabling System SQL injection in index1.php

CVE-2026-11472 · Severity: high · CVSS 7.3 · Published 2026-06-08

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

A vulnerability exists in the SourceCodester Class and Exam Timetabling System, a web application used for managing academic schedules. An attacker can exploit this flaw to bypass security controls and gain unauthorized access to the underlying database. This could lead to the theft of sensitive information, unauthorized modification of schedules, or a complete shutdown of the system.

Technical details

A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the '/index1.php' component. The root cause is the improper neutralization of the 'password' POST parameter, which is used directly in SQL queries without adequate validation or prepared statements. A remote, unauthenticated attacker can exploit this by sending specially crafted malicious SQL queries. Successful exploitation allows for unauthorized database access, sensitive data exfiltration, and potential system compromise. Proof-of-concept exploits, including boolean-based, error-based, and time-based blind injection techniques, have been publicly disclosed.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-05-20: disclosed: Vulnerability details and POC shared on GitHub issue tracker
  • 2026-06-08: advisory: NVD publication date

References

Related threats