CVE-2026-2089: SourceCodester Online Class Record System controller.php sql injection
A vulnerability was found in SourceCodester Online Class Record System 1.0. This vulnerability affects unknown code of the file /admin/subject/controller.php. Performing a manipulation of the argument ID results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-2089?
CVE-2026-2089 is classified as a high severity SQL injection vulnerability.
How do I fix CVE-2026-2089?
To fix CVE-2026-2089, sanitize and validate all user inputs to prevent SQL injection in the controller.php file.
What type of vulnerability is CVE-2026-2089?
CVE-2026-2089 is an SQL injection vulnerability affecting the SourceCodester Online Class Record System.
Which file is affected by CVE-2026-2089?
CVE-2026-2089 specifically affects the /admin/subject/controller.php file.
What can an attacker do with CVE-2026-2089?
An attacker can use CVE-2026-2089 to manipulate the argument ID, potentially gaining unauthorized access to the database.