Impact
A flaw in the forCYS.php endpoint of SourceCodester Class and Exam Timetabling System allows an attacker to insert arbitrary JavaScript by manipulating the 'course' query parameter. The injected script runs in the victim’s browser, enabling cookie theft, session hijacking, phishing attacks or defacement. The weakness is a classic CWE‑79 injection, and its effects are limited to the client side, typically impacting confidentiality and integrity of user data, while potentially disrupting user experience.
Affected Systems
The affected product is SourceCodester Class and Exam Timetabling System version 1.0 as distributed by SourceCodester.
Risk and Exploitability
The CVSS score of 5.1 signals a moderate severity, and the EPSS score of less than 1 % indicates a low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit it remotely by directing victims to a crafted link that includes a malicious 'course' value; no server‑side compromise is required and the exploit is publicly documented.
OpenCVE Enrichment