Impact
A flaw exists in the SourceCodester Class and Exam Timetabling System 1.0 file /CYS.php where manipulating the "course" argument permits the insertion of arbitrary script code. The vulnerability is an XSS defect that can be triggered remotely and has been publicly disclosed. An attacker can exploit this to inject malicious JavaScript that runs in the victim’s web browser, potentially leading to session hijacking, credential theft or defacement of the application interface.
Affected Systems
The known affected product is SourceCodester Class and Exam Timetabling System version 1.0. The vulnerability is present in this release and may affect any deployment of the software that exposes the /CYS.php endpoint to user input.
Risk and Exploitability
The CVSS score of 5.1 indicates a medium severity impact. The EPSS score is below 1%, suggesting a very low likelihood of widespread exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Attackers can remotely craft carefully crafted "course" parameter values to inject scripts. Successful exploitation could compromise user sessions or compromise the confidentiality of sensitive data stored in the client browser context. Because the flaw resides in a publicly accessible PHP script, it can be triggered by any user with network access to the web server.
OpenCVE Enrichment