Impact
A reflected cross‑site scripting vulnerability exists in the BSIS.php module of SourceCodester Class and Exam Timetabling System 1.0. By manipulating the 'day' query parameter an attacker can inject arbitrary client‑side script that will execute in the browser of any user who visits the affected page. This flaw arises from improper handling and insufficient output encoding of user input and is classified as CWE-79 and CWE-94. The injected script could hijack user sessions, deface content, or perform other malicious actions within the victim’s browser context.
Affected Systems
Only the documented affected product is SourceCodester Class and Exam Timetabling System version 1.0; no other versions or related products are reported as vulnerable in the CVE data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score of <1% reflects a low but non‑zero probability of active exploitation. The flaw can be triggered remotely by sending a crafted HTTP request to the 'day' parameter without authentication, and a public exploit demonstrates the ease of use. The vulnerability is not listed in the CISA KEV catalog, indicating that widespread exploitation has not yet been documented.
OpenCVE Enrichment