Retour à la veille
CVE-2026-86224
Score CVSS
7.3
HIGH
Description détaillée
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected is the function mysqli_query of the file /admin/modal_add_product.php. Executing a manipulation of the argument fname can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.
Vecteur d'attaque (CVSS)
Vecteur brut :CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Dernières Vulnérabilités
CVE-2026-84820
Unauthenticated Cross Site Scripting (XSS) in Unlimited Elements For Elementor (Free Widgets, Addons, Templates) <= 2.0.17 versions.
VOIR DÉTAILS
CVE-2026-84818
Unauthenticated Cross Site Scripting (XSS) in Open User Map <= 1.4.50 versions.
VOIR DÉTAILS
CVE-2026-84817
Unauthenticated Cross Site Scripting (XSS) in JetFormBuilder <= 3.6.5.1 versions.
VOIR DÉTAILS
