Impact
The flaw is a reflected cross‑site scripting vulnerability in the forexam.php page of SourceCodester Class and Exam Timetabling System 1.0. By manipulating the user supplied "day" query parameter, an attacker can inject arbitrary JavaScript that will execute in the browser of anyone who visits the crafted URL. Based on typical XSS consequences, an attacker could potentially steal session cookies, redirect users to malicious sites, or deface the application – impacts that are inferred from the nature of the flaw rather than explicitly stated in the CVE description.
Affected Systems
The vulnerable component is the forexam.php script in SourceCodester Class and Exam Timetabling System, version 1.0. No other product versions or vendors are listed as affected by the current advisory.
Risk and Exploitability
The CVSS score of 5.1 indicates a moderate risk rating, while the EPSS score of less than 1% suggests that practical exploitation cases are currently rare. The attack path is remote – an attacker only needs to persuade a user to visit a malicious link. A proof‑of‑concept is already publicly available, but the vulnerability is not catalogued in the CISA KEV database. Based on typical XSS scenarios, the threat becomes more concerning if the system is exposed to untrusted users or can be accessed from the public Internet.
OpenCVE Enrichment