Sceawere

Vulnerability Detail

CVE-2026-78055UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Class and Exam Timetabling System Cross Site Scripting

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
3h ago
Vendor
SourceCodester
Product
Class and Exam Timetabling System
Attack Type
Cross Site Scripting
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-23T02:17:00.243Z",
  "pubdate": "2026-08-23T02:17:00.243Z",
  "executiveSummary": "An unauthenticated Cross-Site Scripting (XSS) vulnerability has been identified in SourceCodester Class and Exam Timetabling System version 1.0. The security flaw resides in the handling of the course parameter processed by the /BSIT2.php file. Successful exploitation of this vulnerability allows remote attackers to inject malicious client-side scripts, typically JavaScript, into web pages rendered to other users of the application.\nThe primary impact of this vulnerability includes session hijacking, credential theft, redirection to malicious infrastructure, and unauthorized actions performed within the context of the victim's browser session. Given that the exploit has been publicly disclosed and remote exploitation is feasible without prior authentication, the overall risk to deployed instances is significant. Attackers require no specialized privileges or internal network access, as the attack vector relies solely on inducing a user to interact with a crafted HTTP request targeting the exposed web application.\nRemediation requires the application of robust input sanitization and context-aware output encoding to neutralize potentially malicious payloads submitted via the course argument before they are reflected back to the client.",
  "technicalDetails": "The vulnerability is classified as Cross-Site Scripting (XSS), stemming from improper input validation and output handling within the PHP-based web application. Specifically, the vulnerable component is the /BSIT2.php file, which accepts user-supplied input via the course parameter. The root cause of the issue lies in the direct reflection of this input into the Hypertext Markup Language (HTML) response without adequate sanitization, escaping, or encoding mechanisms.\nAttack flow begins when a remote attacker crafts a malicious Uniform Resource Locator (URL) or an HTTP request containing arbitrary JavaScript payload strings substituted into the course parameter of /BSIT2.0.php. Because the application fails to validate or neutralize the incoming data, the payload is processed and subsequently embedded directly into the Document Object Model (DOM) of the page returned to any user visiting the constructed link. When the victim's browser renders the response, the injected script executes within the security context of the victim's active session, allowing the attacker to bypass access controls, manipulate page content, or exfiltrate sensitive session tokens and cookies.\nThe vulnerability is present in version 1.0 of the SourceCodester Class and Exam Timetabling System. Exploitation requires network exposure over standard web protocols (HTTP/HTTPS) and can be executed remotely by unauthenticated entities. No specific privilege requirements exist to trigger the injection, and the attack vector relies entirely on reflected XSS mechanics where the malicious payload is executed immediately upon the victim rendering the server response containing the unsanitized parameter."
}
CVE-2026-78055: Class and Exam Timetabling System Cross Site Scripting (MEDIUM Severity, CVSS: 4.3) - Sceawere