CVE-2026-85512: SourceCodester Class and Exam Timetabling System session.php authorization
Published Sep 4, 2026
·Updated
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Sep 4, 2026
CVE Published
via MITRE·10:15 AM
Data Sourced
via MITRE·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an authenticated account or user interaction?
No. The vulnerability is rated PR:N and UI:N, and the attack can be executed remotely by manipulating the ID argument.
2
Which systems should be prioritized for investigation?
Deployments of SourceCodester Class and Exam Timetabling System 1.0 should be investigated, particularly where the /admin/session.php endpoint is remotely reachable.
3
Is exploit code available publicly?
Yes. The exploit has been released publicly and may be used in attacks.