Description
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-04
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in SourceCodester Class and Exam Timetabling System version 1.0, specifically within the code of /admin/session.php. By manipulating the ID argument, an attacker can bypass authentication checks, resulting in missing authorization. This vulnerability enables a remote actor to gain unauthorized access to administrative functions or sensitive data that should otherwise be protected.

Affected Systems

The affected product is the SourceCodester Class and Exam Timetabling System, version 1.0. No alternative versions or updates are listed, and the vulnerability details apply to the existing installation of this product.

Risk and Exploitability

With a CVSS score of 6.9, the risk is considered moderate. The exploit is available publicly and can be launched remotely by altering the ID parameter in web requests. Because EPSS information is not available and the vulnerability is not listed in CISA's KEV catalog, the likelihood of exploitation remains uncertain but the public availability of the exploit code elevates the potential threat. Official remediation is not documented, so administrators should treat the issue as a serious privilege escalations risk until a fix or mitigation becomes available.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Identify whether the system is running SourceCodester Class and Exam Timetabling System 1.0 and confirm exposure to the web.
  • Apply a vendor‑supplied patch or upgrade to the latest version that addresses the session authorization flaw, if such a release is available.
  • Restrict access to the /admin/session.php endpoint to trusted network ranges or apply firewall rules to limit remote exposure.
  • Monitor application logs for abnormal ID parameters and unauthorized administrative activity, and investigate any suspicious events promptly.

Generated by OpenCVE AI on September 4, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 04 Sep 2026 10:30:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This vulnerability affects unknown code of the file /admin/session.php. The manipulation of the argument ID results in missing authorization. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Class and Exam Timetabling System session.php authorization
First Time appeared Sourcecodester
Sourcecodester class And Exam Timetabling System
Weaknesses CWE-862
CWE-863
CPEs cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester class And Exam Timetabling System
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Class And Exam Timetabling System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-04T10:15:10.908Z

Reserved: 2026-09-04T05:34:15.693Z

Link: CVE-2026-85512

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-04T11:17:19.433

Modified: 2026-09-04T11:17:19.433

Link: CVE-2026-85512

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-04T11:30:17Z

Weaknesses