CVE-2026-90615: SourceCodester Class and Exam Timetabling System subject1.php cross site scripting
Published Sep 14, 2026
·Updated
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.
Affected Software
1 affected component
Sourcecodester Class and Exam Timetabling System=1.0
Event History
Sep 14, 2026
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require authentication or user interaction?
Authentication is not required, and the attack can be executed remotely. Successful exploitation requires user interaction.
2
Which systems should be assessed first?
Assess deployments of SourceCodester Class and Exam Timetabling System version 1.0, particularly exposure of the /subject1.php endpoint and its subject argument handling.
3
Is exploit information publicly available?
Yes. The exploit has been publicly disclosed and may be used.