CVE-2026-90526: SourceCodester School Registration and Fee System save_class.php sql injection
A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impacts an unknown function of the file /bilal/saveclass.php. The manipulation of the argument Category leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker can exploit the issue remotely by manipulating the Category argument sent to /bilal/save_class.php. No authentication or user interaction is required according to the supplied CVSS vector.
Which deployments are known to be affected?
The affected product is SourceCodester School Registration and Fee System version 1.0. The vulnerable functionality is associated with /bilal/save_class.php, although the specific function within that file is not identified.
How likely is exploitation?
A public exploit has been disclosed and may be used. The vulnerability is rated high severity, with low attack complexity and network-based attack access.