Impact
The vulnerability occurs in the unknown function of /subject.php when the subject argument is supplied. An attacker can insert malicious JavaScript that is rendered by the victim’s browser, resulting in a client‑side code injection flaw. This flaw is consistent with CWE‑79 and also involves code generation identified as CWE‑94. The flaw is exploitable remotely by sending a crafted HTTP request, and the exploit code is publicly available.
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System version 1.0. It is present in the default distribution and no other versions are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The EPSS score is lower than 1 % and the vulnerability is not listed in the CISA KEV catalog. An attacker who can reach the web application can exploit the flaw by including malicious content in the subject parameter; no special prerequisites are required beyond network access.
OpenCVE Enrichment