Vulnerabilidad · Publicado 07/09/2026
Se ha identificado una vulnerabilidad de inyección SQL en el archivo /delete_subject.php del sistema SourceCodester Class and Exam Timetabling System versión 1.0, explotable remotamente mediante manipulación del parámetro ID. El exploit está públicamente disponible y afecta principalmente a instituciones educativas en LATAM que utilizan esta solución para gestión académica. Con CVSS 7.3, representa un riesgo elevado de acceso no autorizado a bases de datos y manipulación de información académica.
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. Impacted is an unknown function of the file /delete_subject.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be used for attacks.
Score: 7.3/10 — Severidad: HIGH — Estado NIST: Received
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
CWE-74, CWE-89
Publicado en NIST NVD.