SQL Injection Vulnerability in SourceCodester Class and Exam Timetabling System
CVE-2026-13527
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 29 June 2026
Badges
What is CVE-2026-13527?
A SQL injection vulnerability exists in the preview4.php file of SourceCodester's Class and Exam Timetabling System version 1.0. This vulnerability arises from improper handling of the 'course_year_section' parameter, allowing attackers to manipulate SQL queries and potentially access sensitive data. The exploit can be executed remotely, posing a significant risk to the system's integrity. Users and administrators are advised to implement protective measures and update to the latest versions as fixes become available.
Affected Version(s)
Class and Exam Timetabling System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
