Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-13485: SourceCodester Class and Exam Timetabling System 1.0 SQL Injection Risk
CVE-2026-13485
Summary
A security risk has been discovered in SourceCodester Class and Exam Timetabling System version 1.0. This could allow an attacker to access or modify sensitive data remotely. To protect your system, update to the latest version or patch the vulnerable file, /preview.php.
Original title
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_s...
Original description
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
5.5
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026