PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-86225 SourceCodester CVE debrief

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is the function mysqli_query of the file /admin/modal_add_room.php. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used.

Vendor
SourceCodester
Product
Class and Exam Timetabling System
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-06
Original CVE updated
2026-09-06
Advisory published
2026-09-06
Advisory updated
2026-09-06

Who should care

Defenders responsible for SourceCodester Class and Exam Timetabling System 1.0 deployments should assess exposure and prioritize patching or mitigation. This includes operators, platform administrators, vulnerability management teams, and security teams who need to verify potential SQL injection attacks, assess exposure of /admin/modal_add_room.php, and prioritize patching or mitigation. Defenders should care about CVE-2026-86225 because it affects SourceCodester Class and Exam Timetabling System 1.0, allowing for potential SQL injection attacks. The attack is possible to be carried out remotely, and the exploit is publicly available. Defenders should review compensating controls for exposed systems while remediation is scheduled and verified, and track exceptions, retest remediated assets, and close the item only after evidence is documented. They should also check relevant monitoring, detection, and logs for exposed assets that need extra review. In addition, defenders should confirm whether affected product deployments exist in managed environments and assign an owner for follow-up. They should review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance, and plan vendor-supported updates or mitigations through normal change control where exposure is confirmed. Finally, they should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available, and monitor for potential exploitation attempts. This may involve verifying the presence of this vulnerability in systems, assessing exposure, and prioritizing patching or mitigation, as well as reviewing compensating controls and tracking exceptions. The goal is to ensure that defenders are aware of the vulnerability and take necessary steps to mitigate it. Therefore, defenders should assess their exposure, prioritize patching or mitigation, and verify the presence of this vulnerability in their systems. They should also apply patches or mitigations as available, monitor for potential exploitation attempts, and review compensating controls for exposed systems while remediation is scheduled and verified. Moreover

Why it matters

Defenders should care about CVE-2026-86225 because it affects SourceCodester Class and Exam Timetabling System 1.0, allowing for potential SQL injection attacks. The attack is possible to be carried out remotely, and the exploit is publicly available.

  • Verify potential SQL injection attacks
  • Assess exposure of /admin/modal_add_room.php
  • Prioritize patching or mitigation

Technical summary

The vulnerability affects the function mysqli_query of the file /admin/modal_add_room.php in SourceCodester Class and Exam Timetabling System 1.0. The manipulation of the argument room_name leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their systems and applying patches or mitigations as available.

Recommended defensive actions

  • Verify the presence of this vulnerability in your systems
  • Apply patches or mitigations as available
  • Monitor for potential exploitation attempts
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, including its description, CVSS score, and affected components. Defenders should verify the presence of this vulnerability in their systems, assess exposure, and prioritize patching or mitigation. The exploit is publicly available, and defenders should be cautious of potential SQL injection attacks. The vulnerability affects the function mysqli_query of the file /admin/modal_add_room.php in SourceCodester Class and Exam Timetabling System 1.0.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-86225 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-86225

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-86225 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-86225

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.