Impact
A remote cross‑site scripting flaw exists in the exam.php file of SourceCodester Class and Exam Timetabling System. Attacking the "day" argument allows insertion of arbitrary JavaScript that executes in the context of viewing users. The flaw permits the execution of user‑controlled scripts during a user’s session.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0. No newer versions or update information is listed in the advisory.
Risk and Exploitability
The CVSS base score is 5.3, denoting a moderate risk level. The EPSS score is below 1%, indicating that public exploitation is presently unlikely. The issue is not listed in CISA’s KEV catalog. The vulnerability can be triggered through a standard HTTP request from a remote location, requiring only the ability to manipulate the "day" parameter.
OpenCVE Enrichment