Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-13486: SourceCodester Class and Exam Timetabling System SQL Injection
CVE-2026-13486
Summary
A vulnerability in the SourceCodester Class and Exam Timetabling System allows an attacker to inject malicious SQL code, potentially exposing sensitive data. This issue can be exploited remotely, and since the exploit has been publicly disclosed, it's essential to update the system to prevent unauthorized access. We recommend taking immediate action to patch or upgrade the system to a secure version.
Original title
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument co...
Original description
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument course_year_section can lead to sql injection. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
5.5
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026