What is CVE-2026-16485?
A vulnerability in SourceCodester Class and Exam Timetabling System 1.0 allows remote XSS attacks via improper handling of the `day` argument in `class.php`. This could lead to malicious script execution in a user's browser; input sanitization and applying the latest patch are recommended.
Azərbaycanca: SourceCodester Class and Exam Timetabling System 1.0 versiyasında `class.php` faylındakı `day` arqumentinin manipulyasiyası ilə uzaqdan XSS (Cross Site Scripting) hücumuna yol açan zəiflik aşkarlanıb. Təsirlənən sistemlərdə zərərli skript icrası mümkündür, istifadəçi girişlərinin filtirlənməsi və son patch-in tətbiqi tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ1
In which file of SourceCodester Class and Exam Timetabling System 1.0 does the vulnerable `day` argument cause an XSS issue?
The vulnerability is caused by improper handling of the `day` argument in the `class.php` file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.