Impact
The flaw is a reflected cross‑site scripting vulnerability in /forsubject.php. By altering the subject argument, an attacker can inject arbitrary JavaScript that executes when a user views the page. This injection exploits the lack of input validation and allows client‑side code to run in the context of the victim's session.
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System, version 1.0, distributed by SourceCodester. No other versions or product modules are listed in the advisory.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the moderate range, and the EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. An attacker can remotely trigger the injection by crafting a URL or submitting a form that contains a malicious payload in the subject field, but the description does not specify whether authentication is required.
OpenCVE Enrichment