CVE-2026-13527: high vulnerability (CVSS 7.3)
CVE-2026-13527 affects SourceCodester Class and Exam Timetabling System 1.0 via SQL injection on /preview4.php. Remote exploitation is possible, and a public exploit is available, raising the risk of compromise.
Prioritize patching or isolating systems running this software. Monitor for unusual database queries and deploy WAF rules to mitigate SQL injection attempts.
CVE-2026-13527 is a critical SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0. It resides in the /preview4.php file, where the course_year_section parameter can be manipulated to execute unauthorized SQL queries.
The vulnerability allows remote attackers to exploit the system, potentially leading to data exfiltration or unauthorized access. A public exploit has been disclosed, increasing the likelihood of active exploitation.
Administrators should immediately apply patches if available or implement input validation and parameterized queries to mitigate the risk. Regularly monitor logs for suspicious database activity.