CVE-2026-13526: SourceCodester Class and Exam Timetabling System edit_class.php sql injection
A flaw has been found in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /editclass.php. This manipulation of the argument ID causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13526?
The severity of CVE-2026-13526 is high with a score of 7.3.
How do I fix CVE-2026-13526?
To fix CVE-2026-13526, validate and sanitize the input parameters in the edit_class.php file to prevent SQL injection.
What type of vulnerability is CVE-2026-13526?
CVE-2026-13526 is an SQL injection vulnerability that allows an attacker to manipulate database queries.
Who is impacted by CVE-2026-13526?
Anyone using SourceCodester Class and Exam Timetabling System version 1.0 is impacted by CVE-2026-13526.
Can CVE-2026-13526 be exploited remotely?
Yes, CVE-2026-13526 can be exploited remotely due to its exposure in the edit_class.php file.