Sceawere

Vulnerability Detail

CVE-2026-78054UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Class and Exam Timetabling System Cross-Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
4h ago
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-23T01:17:19.963Z",
  "pubdate": "2026-08-23T01:17:19.963Z",
  "executiveSummary": "A security vulnerability has been identified in SourceCodester Class and Exam Timetabling System 1.0, specifically within an unknown function handling user-supplied input in the file /BSIS1.php.\nThe identified weakness is classified as a Cross-Site Scripting (XSS) vulnerability, which allows remote attackers to inject malicious client-side scripts, typically written in JavaScript, into web pages viewed by other users.\nThe primary impact of this vulnerability includes session hijacking, credential theft, redirection to malicious destinations, and unauthorized actions performed within the context of the victim's browser session.\nThe affected product is SourceCodester Class and Exam Timetabling System version 1.0, exposing systems utilizing this software to remote exploitation.\nThe risk implications are elevated due to the public availability of exploit material, lowering the barrier to entry for malicious actors seeking to compromise vulnerable installations.\nExploitation requires the attacker to successfully manipulate the vulnerable course parameter and induce a victim to interact with the malicious input, thereby executing arbitrary script code within the user's browser environment.",
  "technicalDetails": "The vulnerability resides in the input handling mechanism of the file /BSIS1.php within SourceCodester Class and Exam Timetabling System 1.0.\nThe root cause of the issue is the lack of proper input sanitization, validation, and contextual output encoding of user-supplied data passed via the course parameter.\nWhen a user or attacker submits specially crafted input containing HTML or JavaScript payloads into the vulnerable course parameter, the application improperly reflects the input directly into the HyperText Markup Language response without neutralizing potentially dangerous characters.\nThe attack vector is network-based and can be executed remotely, requiring no prior authentication or elevated privileges depending on how the application exposes the vulnerable endpoint.\nThe attack flow proceeds as follows: First, the attacker crafts a malicious Uniform Resource Locator (URL) or payload containing arbitrary JavaScript designed to execute within the victim's browser session. Second, the attacker induces a target user to navigate to the manipulated link targeting /BSIS1.php with the malicious course argument. Third, the server processes the request and embeds the unsanitized input directly into the resulting HyperText Markup Language document returned to the browser. Finally, the victim's browser parses the response, executes the embedded script within the security context of the vulnerable application, and fulfills the attacker's objective.\nThe post-exploitation impact includes the potential compromise of user sessions, exposure of sensitive session tokens or cookies, defacement of the web interface, and the execution of unauthorized transactions on behalf of authenticated users."
}
CVE-2026-78054: Class and Exam Timetabling System Cross-Site Scripting (MEDIUM Severity, CVSS: 4.3) - Sceawere