CVE-2026-14772: SourceCodester Class and Exam Timetabling System edit_course1.php sql injection
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0/1.php. The impacted element is an unknown function of the file /editcourse1.php. The manipulation of the argument ID leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14772?
The severity of CVE-2026-14772 is rated as high with a score of 7.3.
What type of vulnerability is CVE-2026-14772?
CVE-2026-14772 is classified as an SQL injection vulnerability.
How can CVE-2026-14772 be exploited?
CVE-2026-14772 can be exploited through remote access by manipulating the ID argument in the edit_course1.php file.
What versions of the SourceCodester Class and Exam Timetabling System are affected by CVE-2026-14772?
CVE-2026-14772 affects SourceCodester Class and Exam Timetabling System versions 1.0.
How do I fix CVE-2026-14772?
To fix CVE-2026-14772, ensure that input validation and parameterized queries are implemented in the affected edit_course1.php file.