SECURITYHIGHCVE-2026-14770

CVE-2026-14770: SQL Injection in SourceCodester Class and Exam Timetabling System

A high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote attackers to manipulate backend database...

Dylan H.

Security Team

July 6, 2026
4 min read
CVE-2026-14770: SQL Injection in SourceCodester Class and Exam Timetabling System

Affected Products

  • SourceCodester Class and Exam Timetabling System 1.0

Executive Summary

CVE-2026-14770 is a high-severity SQL injection vulnerability in SourceCodester Class and Exam Timetabling System 1.0. The flaw exists in the /edit_room.php file, where unsanitized user-supplied input is passed directly into SQL queries. A remote attacker can exploit this to read, modify, or delete database content without any special privileges.

CVSS Score: 7.3 (High)


Vulnerability Overview

AttributeValue
CVE IDCVE-2026-14770
CVSS Score7.3 (High)
TypeSQL Injection (CWE-89)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
Confidentiality ImpactHigh
Integrity ImpactLow
Availability ImpactLow

Affected Component

The vulnerable function resides in /edit_room.php within SourceCodester Class and Exam Timetabling System 1.0, a PHP-based academic scheduling application commonly deployed in educational institutions. The affected parameter passes user-controlled input directly into a SQL query without parameterization or adequate sanitization.

ComponentVersion
SourceCodester Class and Exam Timetabling System1.0
Affected File/edit_room.php
Vulnerability TypeSQL Injection

Technical Analysis

Root Cause

The /edit_room.php endpoint accepts a room identifier parameter and constructs a SQL query by concatenating the unsanitized input directly into the query string. This classic error allows an attacker to inject arbitrary SQL syntax.

-- Example of vulnerable query construction (illustrative)
$query = "SELECT * FROM rooms WHERE id = " . $_GET['id'];

Because no prepared statements or parameterized queries are used, an attacker can append SQL metacharacters to break out of the intended query context.

Exploitation

An attacker can exploit this vulnerability by crafting a malicious HTTP request to the /edit_room.php endpoint with a manipulated parameter value. Depending on the database configuration, this may allow:

  • Data exfiltration — Reading sensitive records including student data, exam schedules, and credentials
  • Authentication bypass — Manipulating login queries to gain unauthorized access
  • Data manipulation — Altering or deleting records in the timetabling database
  • Potential for stacked queries — Depending on the PHP database driver, executing multiple statements

Remediation

Immediate Actions

  1. Apply parameterized queries — Replace all direct SQL string concatenation in /edit_room.php with prepared statements using PDO or MySQLi
  2. Input validation — Validate that room ID parameters are strictly numeric before processing
  3. Least privilege database accounts — Ensure the application's database user has only the minimum required permissions
  4. Web Application Firewall — Deploy WAF rules to detect and block SQL injection patterns while a patch is prepared

Secure Code Example

// Vulnerable pattern:
$id = $_GET['id'];
$query = "SELECT * FROM rooms WHERE id = $id";
 
// Secure pattern using PDO:
$stmt = $pdo->prepare("SELECT * FROM rooms WHERE id = :id");
$stmt->execute(['id' => (int)$_GET['id']]);
$result = $stmt->fetch();

Context

SourceCodester provides free, open-source PHP project templates widely used by students and small educational institutions. These applications are frequently deployed without modification and often lack security hardening. SQL injection vulnerabilities in this codebase are a recurring issue — organizations using any SourceCodester product in production should audit all user-facing input handlers.

Risk Assessment for Deployed Instances

FactorAssessment
Exploit complexityLow — standard SQL injection techniques apply
Public exposureApplications are commonly internet-facing
Data at riskStudent records, exam schedules, admin credentials
Patch availabilityNo official patch released — manual remediation required
UrgencyHigh — no authentication required to exploit

Recommendations

  1. Do not deploy SourceCodester applications in production without a thorough security review and code hardening
  2. Audit all database-interacting scripts for parameterized query usage
  3. Restrict access to the timetabling system behind authentication and network controls
  4. Monitor database logs for unusual query patterns or error spikes
  5. Consider replacement with a maintained, security-audited scheduling solution for academic environments

References