A new critical SQL injection has been discovered in SourceCodester Class and Exam Timetabling System version 1.0, with a public exploit already available. The vulnerability, CVE-2026-14770, affects the /edit_room.php in SourceCodester Timetabling and allows remote exploitation without authentication.

The new vulnerability in this system has a CVSS score of 7.5 (HIGH), highlighting the severity of the risk. SourceCodester Class and Exam Timetabling System is a popular open source platform for educational institutions and curriculum management systems worldwide.
See also: CISA: Urgent patch order for critical Drupal vulnerability
Details of the SourceCodester Timetabling vulnerability
The flaw in the vulnerable system is specifically located in the handling of the ID parameter of the /edit_room.php file . A remote attacker can manipulate the ID parameter and insert malicious SQL statements directly into the system database.
The official CVE-2026-14770 entry states that the exploit is already public and ready for use by malicious actors. The vulnerability does not require authentication, which makes it particularly dangerous for exposed installations of the SourceCodester Class and Exam Timetabling System.
The CVSS 3.1 score reaches 7.5 (HIGH), while CVSS 4.0 rates the issue as MEDIUM. Despite the differentiation, the public availability of exploits for this platform significantly raises the actual risk of exploitation.

Who is affected by the vulnerability?
This particular platform is mainly used by universities, colleges, and schools to manage course syllabi and exams. Educational institutions that have deployed the system on a public web server face immediate risk from this bug.
See also: Ghost CMS vulnerability: 700+ sites compromised and ClickFix attacks
Attackers can exploit the issue in this system to extract sensitive data from students, faculty, and administrative staff. Possible outcomes include leaking personal information, modifying grades, corrupting scheduling data, and completely taking over the system.
The nature of the flaw also allows the recovery of credentials of other users, potentially leading to lateral movement within the educational institution's network. Attackers who exploit the CVE-2026-14770 vulnerability can use the system as an initial entry point for broader attacks within the organization's infrastructure.
Technical analysis of the exploit
The issue in the /edit_room.php of SourceCodester Timetabling arises from the lack of input sanitization for the ID. The code directly inserts the user's value into an SQL query without using prepared statements or parameterized queries.
A typical exploit payload could be of the form ?ID=1' UNION SELECT username,password FROM users--. The attack is executed via a simple HTTP GET request to the vulnerable endpoint, requiring no special tools beyond a browser or curl. Security researchers have confirmed the ease of replication of the attack, which increases the risk of mass exploitation.

Response and mitigation measures
Since SourceCodester Class and Exam Timetabling System is an open source project with limited official support, administrators must implement fixes themselves. The immediate suggested solution includes replacing raw SQL queries with prepared statements and parameterized queries.
See also: Vulnerability in LiteLLM leads to unauthenticated RCE
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Additional protective measures against SQL injection in SourceCodester Timetabling include installing a Web Application Firewall (WAF) in front of the web server, using input validation on all URL parameters, and restricting the permissions of the database user used by the application.
Educational institutions that cannot immediately fix the code should consider temporarily removing the system from public access or placing it behind a VPN gateway. Monitoring web server logs for suspicious SQL patterns is also a critical measure for detecting ongoing attacks.
At the same time, IT managers should check database logs for traces of already executed attacks, as the publication of the exploit may have preceded the official CVE registration.
According to recent cybersecurity research, educational institutions are often targeted by SQL injection attacks due to limited security budgets and extensive use of older open source applications. This phenomenon is exacerbated by the increased digitalization of educational institutions’ administrative processes in recent years. At the same time, the lack of specialized IT staff at many universities is delaying the implementation of necessary security updates.
The recommendations of the SecNews editorial team
The SecNews technical team recommends immediate action for any installation of SourceCodester Class and Exam Timetabling System . The CVE-2026-14770 vulnerability combined with the public exploit is a recipe for rapid exploitation by scammers and ransomware groups targeting educational institutions.
Delaying the implementation of the above measures in SourceCodester Timetabling may lead to a breach with significant financial, legal and operational consequences for the affected educational institutions.
