Sourcecodester · Class/Exam Timetabling System · CVE-2026-16485
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Class and Exam Timetabling System version 1.0
**Description**
Remote cross site scripting is possible due to improper handling of the `day` argument within the `/class.php` endpoint. Cross site scripting is a technique where malicious scripts are injected into trusted websites.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Avoid using the `day` argument in the `/class.php` endpoint until the issue is resolved.