Multiple SQL Injection Vulnerabilities in SourceCodester and itsourcecode Systems

Multiple SQL Injection Vulnerabilities in SourceCodester and itsourcecode Systems

First seen 7 Sep 2026, 09:23 UTC Redpacketsecuritygithub.comvuldb.com 69.0

Article Content

Browse articles
ThreatCluster

Three critical SQL injection vulnerabilities have been identified in SourceCodester Class and Exam Timetabling System and itsourcecode School Management System. CVE-2026-86224 and CVE-2026-86225 affect the Class and Exam Timetabling System, allowing unauthenticated remote attackers to exploit the mysqli_query function and manipulate timetable data. CVE-2026-86268 impacts the itsourcecode School Management System, enabling similar attacks through the User_Login.php file. All vulnerabilities are publicly disclosed and pose high risks to internet-facing deployments, particularly affecting schools and small organizations. Exploitation could lead to unauthorized data access, disruption of services, and further compromise of connected systems. Immediate remediation is advised, including applying vendor fixes or restricting application exposure. The vulnerabilities were published on September 6 and 7, 2026.

Key Points: • Three SQL injection vulnerabilities identified in educational software systems. • CVE-2026-86224 and CVE-2026-86225 allow remote exploitation with no authentication needed. • Urgent remediation required due to public exploit availability and high-risk exposure.

Ask AI about this cluster

Timeline

2026-09-06
CVE-2026-86224 published
Vulnerability in SourceCodester Class and Exam Timetabling System allows SQL injection via /admin/modal_add_product.php.
Redpacketsecurity
2026-09-06
CVE-2026-86225 published
Vulnerability in SourceCodester Class and Exam Timetabling System allows SQL injection via /admin/modal_add_room.php.
Redpacketsecurity
2026-09-07
CVE-2026-86268 published
Vulnerability in itsourcecode School Management System allows SQL injection via User_Login.php.
Redpacketsecurity