CVE-2026-78054: SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting
A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
The attack can be launched remotely and requires no privileges, but it requires user interaction. An attacker would need to induce a user to interact with a crafted request or page containing a malicious course parameter.
Which deployments are affected?
The affected product is SourceCodester Class and Exam Timetabling System version 1.0. The vulnerable behavior is associated with the course argument in /BSIS1.php; the available data does not state whether any configuration changes are required.
How mature is exploitation?
A public exploit is available, so the issue could be used in attacks. The supplied assessment rates exploit code maturity as proof-of-concept.