Impact
SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to a cross‑site scripting flaw that can be triggered by manipulating the subject argument in the /subject1.php file. When an attacker supplies specially crafted input, the application echoes that data without proper encoding, allowing the execution of arbitrary JavaScript in the victim's browser. This can lead to cookie theft, defacement, or other client‑side attacks, compromising the confidentiality and integrity of user sessions. The flaw represents a CWE‑79 type vulnerability and also exhibits characteristics of CWE‑94 code injection, as improper neutralization of input allows arbitrary script execution.
Affected Systems
SourceCodester Class and Exam Timetabling System 1.0, as listed in the vendor/product data, is affected. The vulnerability exists in subject1.php through an unknown argument manipulation of the subject parameter. No further version information is available, so any deployment running this version is vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, while the EPSS score is < 1%, and the issue is not listed in the CISA KEV catalog. The attack vector is remote, likely via a web request that includes the manipulated subject value, affecting any user who views the resulting page.
OpenCVE Enrichment