Impact
A cross‑site scripting vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows a remote attacker to inject malicious JavaScript through the course parameter of BSCE2.php. The attacker can load arbitrary code into the browsers of anyone who visits that page, potentially leading to session hijacking, credential theft, or defacement. The flaw is identified as CWE‑79. The CVE also flags CWE‑94, though the description does not detail command‑injection exploitation.
Affected Systems
SourceCodester Class and Exam Timetabling System version 1.0, accessed via /BSCE2.php. The vulnerability stems from how the course argument is handled within that file. Any installation that has not applied a vendor update is susceptible. No additional vendor or product versions were listed.
Risk and Exploitability
CVSS base score of 5.3 indicates a medium‑impact vulnerability. EPSS data is not available but the existence of a publicly documented exploit and the remote launchability imply that the likelihood of attack is non‑negligible. The flaw is not currently listed in the CISA KEV catalog, yet it remains a potential threat for any site that continues to use the unpatched system. Attackers could leverage the vulnerability by sending a crafted request to BSCE2.php with a malicious course value over the internet without authenticating.
OpenCVE Enrichment