CVE-2026-78055: SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker can exploit the issue remotely by manipulating the course argument handled by /BSIT2.php. The CVSS vector indicates no privileges are required, but user interaction is required for impact.
What is the likely impact on an affected user?
The reported impact is limited to integrity, with no reported confidentiality or availability impact. Because this is cross-site scripting, impact depends on a user interacting with attacker-controlled content or a crafted request.
Is a public exploit available?
Yes. The exploit has been publicly disclosed and may be used.