Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
5.5
CVE-2026-13488: SourceCodester Class and Exam Timetabling System SQL Injection Risk
CVE-2026-13488
Summary
An attacker can inject malicious SQL code into the system, potentially stealing or modifying sensitive data. This vulnerability affects the SourceCodester Class and Exam Timetabling System, which may be used to gain unauthorized access to the system. Update the system to the latest version or patch to mitigate this risk.
Original title
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipula...
Original description
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulation of the argument course_year_section results in sql injection. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks.
nvd CVSS2.0
7.5
nvd CVSS3.1
7.3
nvd CVSS4.0
5.5
Vulnerability type
CWE-74
Injection
CWE-89
SQL Injection
Published: 28 Jun 2026 · Updated: 23 Jul 2026 · First seen: 28 Jun 2026