Junglewise Threat Intelligence

CVE-2026-16154: SourceCodester Class and Exam Timetabling System SQL injection in edit_room1.php

CVE-2026-16154 · Severity: high · CVSS 7.3 · Published 2026-07-18

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Class and Exam Timetabling System, a software tool used for managing academic schedules. An attacker can exploit this flaw to gain unauthorized access to the underlying database, potentially leading to the theft of sensitive information or the disruption of scheduling operations. This attack can be carried out remotely without requiring any login credentials.

Technical details

A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the '/edit_room1.php' file. The root cause is the improper neutralization of the 'id' GET parameter before its use in a database query. A remote, unauthenticated attacker can manipulate this parameter to execute arbitrary SQL commands. This can lead to unauthorized data retrieval (including sensitive database contents), data modification, or administrative access. Proof-of-concept exploits, including boolean-based blind, error-based, and UNION-based payloads, have been publicly disclosed. No official patch is currently documented; users are advised to implement prepared statements and input validation.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-06-12: disclosed: Vulnerability reported on GitHub by user zzb1388
  • 2026-07-18: advisory: NVD/VulDB publication date

References

Related threats