Junglewise Threat Intelligence

CVE-2026-16155: SourceCodester Class and Exam Timetabling System XSS in schoolyr.php

CVE-2026-16155 · Severity: low · CVSS 3.5 · Published 2026-07-18

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Class and Exam Timetabling System, a software tool used for managing academic schedules. An attacker can inject malicious scripts into the system that execute when a user views certain pages. This could allow an attacker to perform unauthorized actions on behalf of users or steal sensitive session information.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the /schoolyr.php file. The root cause is the improper neutralization of user-supplied input in the 'sy' parameter, which is subsequently rendered in the web page without adequate encoding or filtering. A remote attacker can exploit this by tricking a logged-in user into clicking a specially crafted link containing a malicious script payload. Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of the victim's browser session, potentially leading to session hijacking or unauthorized administrative actions. A public exploit (PoC) is available.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-06-12: disclosed: Vulnerability reported on GitHub by zzb1388
  • 2026-07-18: advisory: NVD/VulDB advisory published

References

Related threats