HIGHVulnerability

CVE-2026-86224

A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Properties

severity
HIGH
score
7.3
cve_id
CVE-2026-86224
signal_observed_at
2026-09-16T21:37:07+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
published_at
2026-09-06T21:17:22.567
last_modified
2026-09-11T21:17:38.340

Related Entities (3)

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (2)

[Weakness]Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
[Weakness]Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86224 — Ninja Signal Threat Intelligence | Ninja Signal