CVE-2026-86223: SourceCodester Class and Exam Timetabling System modal_add_coursea.php mysqli_query sql injection
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This impacts the function mysqliquery of the file /admin/modaladdcoursea.php. Performing a manipulation of the argument course results in sql injection. Remote exploitation of the attack is possible. The exploit has been made public and could be used.
Affected Software
Event History
Frequently Asked Questions
Which deployments should be treated as affected?
SourceCodester Class and Exam Timetabling System version 1.0 is identified as affected. The vulnerable endpoint is /admin/modal_add_coursea.php.
Does an attacker need authentication or user interaction to exploit this issue?
The supplied vector indicates no privileges and no user interaction are required. Exploitation can be performed remotely over the network.
How likely is exploitation in practice?
A public exploit is available and could be used. The issue is rated high severity, with low impacts to confidentiality, integrity, and availability.