Vulnerabilidad · Publicado 06/09/2026
Se ha descubierto una vulnerabilidad de inyección SQL en el archivo /delete_teacher.php del sistema SourceCodester Class and Exam Timetabling System versión 1.0, mediante manipulación del parámetro ID. Esta falla permite a atacantes remotos ejecutar comandos SQL arbitrarios y comprometer la integridad de bases de datos educativas. El exploit ha sido publicado públicamente, aumentando el riesgo inmediato para instituciones académicas en México y Latinoamérica que utilizan esta plataforma.
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /delete_teacher.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been released to the public and may be used for attacks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.