CVE-2026-15715: SourceCodester Class and Exam Timetabling System exam.php cross site scripting
Published Jul 14, 2026
·Updated
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /exam.php. Such manipulation of the argument day leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Jul 14, 2026
CVE Published
via MITRE·05:45 PM
Data Sourced
via MITRE·05:45 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-15715?
CVE-2026-15715 has a medium severity rating of 4.3.
2
How does CVE-2026-15715 affect the SourceCodester Class and Exam Timetabling System?
CVE-2026-15715 allows for cross-site scripting (XSS) by manipulating the 'day' argument in the '/exam.php' file.
3
Can CVE-2026-15715 be exploited remotely?
Yes, CVE-2026-15715 can be exploited remotely due to its nature.
4
What type of vulnerability is described in CVE-2026-15715?
CVE-2026-15715 is classified as a cross-site scripting (XSS) vulnerability.
5
What is the potential impact of exploiting CVE-2026-15715?
Exploiting CVE-2026-15715 may allow attackers to execute scripts in the context of the user's browser.