CVE-2026-86208: SourceCodester Class and Exam Timetabling System delete_teacher.php sql injection
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /deleteteacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
The attack can be launched remotely by manipulating the ID argument supplied to /delete_teacher.php. No authentication or user interaction requirements are stated in the available data.
Is exploit code available?
Yes. The exploit has been released publicly and may be used in attacks.
Which deployments should be considered exposed?
Deployments of SourceCodester Class and Exam Timetabling System 1.0 with /delete_teacher.php remotely reachable should be considered potentially exposed. The available data does not state whether any particular default configuration restricts access to this endpoint.