CVE-2026-78115: SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php improper authorization
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /admin/edituseraccount.php of the component User Account Update. Such manipulation of the argument id/username leads to improper authorization. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs at least low-level privileges, as indicated by the PR:L metric. The attack can be launched remotely and does not require user interaction.
What does an attacker manipulate to trigger the flaw?
The issue involves manipulation of the id or username argument in /admin/edit_user_account.php within the User Account Update component. This can result in improper authorization.
Is exploit code available?
Yes. The exploit has been publicly disclosed and may be used.