CVE-2026-13521: SourceCodester Class and Exam Timetabling System preview5.php sql injection
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation of the argument courseyearsection leads to sql injection. The attack may be performed from remote. The exploit is publicly available and might be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13521?
The severity of CVE-2026-13521 is classified as high with a score of 7.3.
What type of vulnerability is CVE-2026-13521?
CVE-2026-13521 is a SQL injection vulnerability found in the SourceCodester Class and Exam Timetabling System.
How can I exploit CVE-2026-13521?
An attacker can exploit CVE-2026-13521 by manipulating the course_year_section parameter in the /preview5.php file to execute arbitrary SQL queries.
How do I fix CVE-2026-13521?
To fix CVE-2026-13521, it is recommended to sanitize and validate user input for the course_year_section parameter and implement prepared statements.
What systems are affected by CVE-2026-13521?
CVE-2026-13521 affects version 1.0 of the SourceCodester Class and Exam Timetabling System.