{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/class-and-exam-timetabling-system/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-19899"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Class and Exam Timetabling System"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eSourceCodester Class and Exam Timetabling System version 1.0 is affected by a critical SQL injection vulnerability. The flaw exists within the edit_teacher.php file, where the ID parameter fails to properly neutralize user-supplied input before using it in database queries. This vulnerability allows an unauthenticated, remote attacker to manipulate SQL commands, potentially leading to unauthorized data access, modification, or deletion within the underlying database. The vulnerability has been publicly disclosed with functional exploit code, increasing the risk of active exploitation. Organizations utilizing this software are at risk of complete database compromise if the application is exposed to the internet.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs reconnaissance to identify instances of Class and Exam Timetabling System exposed to the internet.\u003c/li\u003e\n\u003cli\u003eAttacker probes the /edit_teacher.php endpoint to confirm the handling of the ID parameter.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious HTTP GET or POST request containing SQL injection payloads targeting the ID argument.\u003c/li\u003e\n\u003cli\u003eThe application processes the request, passing the unvalidated input directly to the backend database query.\u003c/li\u003e\n\u003cli\u003eThe database executes the injected SQL command, allowing the attacker to bypass authentication or extract sensitive records.\u003c/li\u003e\n\u003cli\u003eAttacker exfiltrates database contents or modifies administrative records to achieve further persistence or impact.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability results in unauthorized access to the application database. This can lead to the exposure of sensitive teacher, student, and scheduling information. Depending on database permissions, an attacker may be able to modify records, delete data, or potentially perform remote code execution if the database configuration allows for file system interactions or administrative command execution.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAudit all web server logs for requests directed at /edit_teacher.php containing SQL-related metacharacters (e.g., single quotes, double dashes, OR 1=1).\u003c/li\u003e\n\u003cli\u003eDeploy the provided Sigma rule to detect attempts at exploiting this specific injection vector.\u003c/li\u003e\n\u003cli\u003eRestrict access to the application from untrusted networks and place it behind a Web Application Firewall (WAF) configured to inspect for SQL injection patterns.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, consider deprecating the use of this software due to the lack of secure development practices indicated by this vulnerability.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-08-15T18:20:05Z","date_published":"2026-08-15T18:20:05Z","id":"https://feed.craftedsignal.io/briefs/2026-08-sourcecodester-sqli/","summary":"SourceCodester Class and Exam Timetabling System 1.0 contains an unauthenticated SQL injection vulnerability in edit_teacher.php that allows remote attackers to compromise database integrity.","title":"SQL Injection in SourceCodester Class and Exam Timetabling System","url":"https://feed.craftedsignal.io/briefs/2026-08-sourcecodester-sqli/"}],"language":"en","title":"CraftedSignal Threat Feed - Class and Exam Timetabling System","version":"https://jsonfeed.org/version/1.1"}