---
id: CVE-2026-86298
title: >-
  A security flaw has been discovered in SourceCodester Class and Exam
  Timetabling System 1.0
summary: >-
  A security flaw has been discovered in SourceCodester Class and Exam
  Timetabling System 1.0. Impacted is an unknown function of the file
  /delete_subject.php. Performing a manipulation of the argument ID results in
  sql injection. It is po…
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-74
  - CWE-89
vendor: SourceCodester
product: Class and Exam Timetabling System
affected:
  - class_and_exam_timetabling_system 1.0
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T14:17:34.153'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86298'
references:
  - url: 'https://github.com/mexics2/vulnerability-report/issues/5'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/cve/CVE-2026-86298'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/906517'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399460'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/399460/cti'
    label: cna@vuldb.com
  - url: 'https://www.sourcecodester.com/'
    label: cna@vuldb.com
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-08T13:39:26.145689Z'
epss: 0.00431
epssPercentile: 0.34571
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
