CVE-2026-13485Disclosure

LOWCVSS 5.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_section results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-28); latest day: 2
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01122Mentions · 2026-06-28: 2Mentions · 2026-06-29: 2PoC Mentioned / Linked · 2026-06-29: 1Patch / Workaround · 2026-06-29: 1Technical Details · 2026-06-29: 206-2806-29
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-282
Disclosure2
2026-06-292
Disclosure1Patch1
Full discourse4 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Remote SQL Injection in preview.php (CVE-2026-13485) SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to SQL injection in /preview.php via the course_year_section parameter, allowing attacker-controlled input to reach database queries. The root cause is improper input validation/unsafe query construction (classic SQL injection) in an unspecified function handling that parameter. Exploitation is remote over HTTP with no special privileges required beyond the ability to send a crafted request, and a public PoC lowers the barrier to active abuse. If exploited, attackers can read/modify database contents, potentially exfiltrate sensitive records, tamper with schedules/users, and in some deployments pivot toward full application compromise depending on DB permissions. 👉 Affected: SourceCodester Class and Exam Timetabling System 1.0 | No fix yet — treat as suspicious

    Post summary

    CVE-2026-13485 is a remote SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0, with a public PoC available, no patch yet, and the potential to read, modify, or exfiltrate sensitive data.

    00020148
    296 followersView on X
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    #CVE-2026-13485 - #SQLi in #SourceCodester Class & Exam Timetabling System 1.0. Unpatched, exploit public.#CVSS 7.3. Update or mitigate immediately. #CVEAlert #infosec #cybersecurity #devsecops #redteam #blueteam #devops #sysadmin #github #gitlab More info: https://www.valtersit.com/cve/CVE-2026-13485/

    Post summary

    The post highlights CVE‑2026‑13485 as an unpatched SQL injection flaw in SourceCodester Class & Exam Timetabling System 1.0 with a CVSS 7.3 score, warns that a public exploit exists, and urges users to apply a patch or mitigation immediately.

    0001098
    965 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-13485 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-13485 ----- Traducción: CVE-2026-13485 Se … http://infoflow.cloud`

    Post summary

    The post announces CVE‑2026‑13485 for SourceCodester Class and Exam Timetabling System 1.0, noting an unknown function of /preview.php, but provides no further exploitation, patch, or technical specifics.

    0000034
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-13485 A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulatio… https://www.cve.org/CVERecord?id=CVE-2026-13485

    Post summary

    The text discloses CVE-2026-13485 affecting /preview.php in SourceCodester Class and Exam Timetabling System 1.0, but offers no further technical or remediation details.

    00000738
    57.7K followersView on X

Explore more