Junglewise Threat Intelligence

CVE-2026-86220: SourceCodester Class and Exam Timetabling System SQL injection in course parameter

CVE-2026-86220 · Severity: high · CVSS 7.3 · Published 2026-09-06

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

SourceCodester Class and Exam Timetabling System is a web application for managing school class schedules and exam timetables. A SQL injection vulnerability in the course parameter of the admin panel allows remote attackers to execute arbitrary database queries, potentially exposing or modifying sensitive academic data and student information without authentication.

Technical details

A SQL injection vulnerability exists in the mysqli_query function call within the /admin/modal_add_course.php file. The vulnerability is triggered through improper sanitization of the "course" parameter, allowing an attacker to inject arbitrary SQL commands. The affected component is the administrative course creation functionality, which is network-accessible and requires no authentication. A successful exploit enables an attacker to read, modify, or delete database records, potentially compromising the integrity and confidentiality of the timetabling system. Patches or updates for this vulnerability have not been confirmed as available.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-09-06: disclosed

References

Related threats