
🚨 HIGH - Remote SQL Injection in preview.php (CVE-2026-13485) SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to SQL injection in /preview.php via the course_year_section parameter, allowing attacker-controlled input to reach database queries. The root cause is improper input validation/unsafe query construction (classic SQL injection) in an unspecified function handling that parameter. Exploitation is remote over HTTP with no special privileges required beyond the ability to send a crafted request, and a public PoC lowers the barrier to active abuse. If exploited, attackers can read/modify database contents, potentially exfiltrate sensitive records, tamper with schedules/users, and in some deployments pivot toward full application compromise depending on DB permissions. 👉 Affected: SourceCodester Class and Exam Timetabling System 1.0 | No fix yet — treat as suspicious
Post summary
CVE-2026-13485 is a remote SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0, with a public PoC available, no patch yet, and the potential to read, modify, or exfiltrate sensitive data.



