Junglewise Threat Intelligence

CVE-2026-16484: SourceCodester Class and Exam Timetabling System SQL injection in edit_subjecta.php

CVE-2026-16484 · Severity: high · CVSS 7.3 · Published 2026-07-21

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

A security vulnerability has been identified in the SourceCodester Class and Exam Timetabling System, a software tool used for managing academic schedules. An attacker can exploit this flaw to gain unauthorized access to the underlying database without needing a username or password. This could lead to the theft of sensitive school data, modification of exam schedules, or disruption of the system's availability.

Technical details

A SQL injection vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the '/edit_subjecta.php' file. The root cause is the improper neutralization of the 'id' GET parameter before it is used in a database query. A remote, unauthenticated attacker can exploit this by sending specially crafted SQL payloads (including boolean-based blind, error-based, and UNION-based techniques) to manipulate database queries. Successful exploitation allows for unauthorized data retrieval, modification, or deletion. No patches are currently reported; remediation should include implementing prepared statements with parameterized queries.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-06-16: disclosed: Vulnerability details and PoC shared on GitHub
  • 2026-07-21: advisory: NVD/VulDB advisory published

References

Related threats