Executive brief
A security vulnerability exists in the SourceCodester Class and Exam Timetabling System, a web application used for managing academic schedules. An attacker can exploit this flaw to gain unauthorized access to the underlying database without needing a username or password. This could lead to the theft of sensitive school data, unauthorized modification of exam schedules, or a complete disruption of the system's operations.
Technical details
A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the '/edit_subject.php' file. The root cause is the improper neutralization of the 'id' GET parameter before it is used in a database query. A remote, unauthenticated attacker can provide malicious SQL payloads (including boolean-based blind, error-based, and UNION-based techniques) to manipulate queries. Successful exploitation allows for unauthorized database access, data exfiltration, and potential administrative takeover. No authentication or user interaction is required to trigger the vulnerability. As of the advisory date, no official patch has been confirmed, and users are advised to implement prepared statements and input validation manually.
Affected products
- SourceCodester Class and Exam Timetabling System 1.0
Timeline
- 2026-06-14: disclosed: Initial vulnerability discovery and PoC shared on GitHub
- 2026-07-19: advisory: NVD and VulDB publish advisory details