CVE-2026-86222: SourceCodester Class and Exam Timetabling System modal_add_course2.php mysqli_query sql injection
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. This affects the function mysqliquery of the file /admin/modaladdcourse2.php. Such manipulation of the argument course leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The vulnerability can be exploited remotely and requires no privileges or user interaction, according to the supplied CVSS vector. An attacker able to send requests to the affected application may be able to target it.
Which component and input are affected?
The affected code is the mysqli_query usage in /admin/modal_add_course2.php. SQL injection is triggered through manipulation of the course argument.
Is public exploit information available?
Yes. The exploit has been publicly disclosed and may be used.