A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0 . It has been declared as critical . The affected element is an unknown function of the file /preview4.php . Such manipulation of the argument course_year_section leads to sql injection. This vulnerability is traded as CVE-2026-13527 . The attack may be launched remotely. Furthermore, there is an exploit available.