Junglewise Threat Intelligence

CVE-2026-16156: SourceCodester Class and Exam Timetabling System XSS in forexam.php

CVE-2026-16156 · Severity: low · CVSS 3.5 · Published 2026-07-18

Technologies: SourceCodester Class and Exam Timetabling System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Class and Exam Timetabling System, a web application used for managing academic schedules. An attacker can inject malicious scripts into the system that execute when other users view specific pages. This could lead to unauthorized actions being performed on behalf of users, the theft of login session information, or the defacement of the scheduling interface.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in SourceCodester Class and Exam Timetabling System 1.0 within the /forexam.php file. The root cause is the improper neutralization of user-provided input in the 'day' parameter before it is rendered in the web page. A remote attacker can exploit this by tricking a user into clicking a specially crafted link or by submitting a malicious payload that executes arbitrary JavaScript in the context of the victim's browser session. This can result in the theft of session cookies or unauthorized actions. While some reports suggest low privileges are required, the vulnerability may be exploitable without authentication depending on the deployment configuration. A public exploit (PoC) has been released.

Affected products

  • SourceCodester Class and Exam Timetabling System 1.0

Timeline

  • 2026-06-12: disclosed: Vulnerability reported on GitHub by zzb1388
  • 2026-07-18: advisory: NVD/VulDB advisory published

References

Related threats