CVE-2026-16485
MEDIUM Exploitation: PoC
4.3
CVSS 3.1
Description
A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.
Metadata
Severity & Metrics
4.3
MEDIUM CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | — | 1.0 |
CVSS scores (4)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 5.3 | MEDIUM | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P |
| 5.0 | N/D | 2.0 | cna | AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR |
| 4.3 | MEDIUM | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
| 4.3 | MEDIUM | 3.0 | cna | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R |
References (6)
- VDB-380943 | SourceCodester Class and Exam Timetabling System class.php cross site scripting https://vuldb.com/vuln/380943
- VDB-380943 | CTI Indicators (IOB, IOC, TTP, IOA) https://vuldb.com/vuln/380943/cti
- CVE-2026-16485 | CVE Analysis and Report https://vuldb.com/cve/CVE-2026-16485
- Submit #859906 | sourcecodester Class and Exam Timetabling System V1.0 cross site scripting https://vuldb.com/submit/859906
- https://github.com/ashfaqsharif47-arch/Web-RCE/issues/1
- https://www.sourcecodester.com/