CVE-2026-13527: SourceCodester Class and Exam Timetabling System preview4.php sql injection
Published Jun 29, 2026
·Updated
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. The affected element is an unknown function of the file /preview4.php. Such manipulation of the argument courseyearsection leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Jun 29, 2026
CVE Published
via MITRE·02:30 AM
Data Sourced
via MITRE·02:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-13527?
The severity of CVE-2026-13527 is classified as high with a score of 7.3.
2
How can I fix CVE-2026-13527?
To fix CVE-2026-13527, sanitize the input for the course_year_section parameter to prevent SQL injection.
3
What type of vulnerability is CVE-2026-13527?
CVE-2026-13527 is an SQL Injection vulnerability.
4
Can CVE-2026-13527 be exploited remotely?
Yes, CVE-2026-13527 can be exploited remotely.
5
What is affected in CVE-2026-13527?
CVE-2026-13527 affects an unknown function in the /preview4.php file of the SourceCodester Class and Exam Timetabling System.