What is CVE-2026-16484?
A SQL injection vulnerability has been identified in the `/edit_subjecta.php` file of SourceCodester Class and Exam Timetabling System 1.0. It allows remote attackers to manipulate the ID argument to interact with the database. It is recommended to update or apply input validation immediately.
Azərbaycanca: SourceCodester Class and Exam Timetabling System 1.0 proqramında `/edit_subjecta.php` faylında SQL injection zəifliyi aşkar edilib. Bu, uzaqdan təsdiqlənməmiş hücumçuya ID arqumentini manipulyasiya edərək verilənlər bazasına təsir etməyə imkan verir. Təhlükəsizlik üçün sistemi dərhal yeniləmək və ya giriş validasiyası əlavə etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
Which file in SourceCodester Class and Exam Timetabling System 1.0 contains the SQL injection vulnerability?
The vulnerability is found in the `/edit_subjecta.php` file.
How can an attacker exploit this SQL injection vulnerability?
A remote unauthenticated attacker can manipulate the ID argument to interact with the database.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.