Description
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting attack via the subject parameter in subject1.php
Action: Apply Patch
AI Analysis

Impact

SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to a cross‑site scripting flaw that can be triggered by manipulating the subject argument in the /subject1.php file. When an attacker supplies specially crafted input, the application echoes that data without proper encoding, allowing the execution of arbitrary JavaScript in the victim's browser. This can lead to cookie theft, defacement, or other client‑side attacks, compromising the confidentiality and integrity of user sessions. The flaw represents a CWE‑79 type vulnerability and also exhibits characteristics of CWE‑94 code injection, as improper neutralization of input allows arbitrary script execution.

Affected Systems

SourceCodester Class and Exam Timetabling System 1.0, as listed in the vendor/product data, is affected. The vulnerability exists in subject1.php through an unknown argument manipulation of the subject parameter. No further version information is available, so any deployment running this version is vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, while the EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, likely via a web request that includes the manipulated subject value, affecting any user who views the resulting page.

Generated by OpenCVE AI on September 15, 2026 at 15:32 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Obtain the latest version of SourceCodester Class and Exam Timetabling System from the vendor, which may contain a fix for this XSS vulnerability.
  • Implement server‑side validation and encoding for the subject parameter, rejecting or escaping any script content before rendering script execution to approved sources and blocks inline scripts.
  • Configure a strict Content Security Policy header that blocks inline scripts or whitelists approved sources to mitigate XSS until a patch is available.

Generated by OpenCVE AI on September 15, 2026 at 15:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 02:15:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Title SourceCodester Class and Exam Timetabling System subject1.php cross site scripting
First Time appeared Sourcecodester
Sourcecodester class And Exam Timetabling System
Weaknesses CWE-79
CWE-94
CPEs cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester class And Exam Timetabling System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Class And Exam Timetabling System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:58:31.338Z

Reserved: 2026-09-12T19:49:36.866Z

Link: CVE-2026-90615

cve-icon Vulnrichment

Updated: 2026-09-15T13:47:29.127Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T02:17:16.030

Modified: 2026-09-15T14:17:24.943

Link: CVE-2026-90615

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:45:19Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')