CVE-2026-86298
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
- EPSS probability
- 0.26%
- CWE
- CWE-89, CWE-74
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- SourceCodester Class and Exam Timetabling System
Weakness type
Related vulnerabilities
- CVE-2026-73698 — FileRun < 2026.3.0 Authenticated SQL Injection via Groups Add Action
- CVE-2026-81800 — WordPress Verified Reviews (Avis Vérifiés) plugin <= 2.4.6 - SQL Injection vulnerability
- CVE-2026-88890 — OpenPanel SQL Injection via unvalidated profile filter column identifier
- CVE-2026-9163 — SQLi in GIS Informatics' GisLab Laboratory Management System
- CVE-2026-78082 — Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP Property < 4.1.4
- CVE-2026-7188 — SQLi in Armiya Information Technologies' Access Control System
- CVE-2026-87925 — Rizwan17 inventory-management-system manage.php storeCustomerOrderInvoice sql injection
- CVE-2026-87921 — Rizwan17 inventory-management-system manage.php update_record sql injection