CVE-2026-16227: SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /editsubject.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16227?
The severity of CVE-2026-16227 is rated high with a score of 7.3.
How does CVE-2026-16227 affect the SourceCodester Class and Exam Timetabling System?
CVE-2026-16227 affects the editing function in the edit_subject.php file, which is vulnerable to SQL injection.
What kind of attack can be executed using CVE-2026-16227?
An attacker can perform a remote SQL injection attack by manipulating the argument ID in the edit_subject.php file.
How can I fix CVE-2026-16227?
To fix CVE-2026-16227, sanitize and validate input parameters in the edit_subject.php file to prevent SQL injection.
Is CVE-2026-16227 exploitable from remote locations?
Yes, CVE-2026-16227 is exploitable from remote locations.