Impact
The vulnerability in the schoolyr.php file of SourceCodester Class and Exam Timetabling System 1.0 allows an attacker to supply a crafted 'sy' parameter value that is reflected in the response without proper encoding, resulting in a cross‑site scripting flaw. The exposed script execution is limited to the client browser, enabling the attacker to run arbitrary JavaScript in the context of users who visit the affected page. This can lead to session hijacking, data theft, or phishing attempts, but does not provide direct server‑side code execution.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0 is the only product listed as affected. No other vendors or product lines are mentioned in the provided data or references, and the vulnerability is tied specifically to the schoolyr.php script of this version.
Risk and Exploitability
The CVSS score of 5.1 classifies the issue as medium severity, while the EPSS score of less than 1% indicates a low likelihood of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog, further suggesting that it has not been reported as a known exploited vulnerability. The flaw can be triggered remotely by sending malicious content in the 'sy' query parameter to the publicly accessible schoolyr.php endpoint.
OpenCVE Enrichment