What is CVE-2026-16486?
This CVE identifies a cross site scripting (XSS) vulnerability in SourceCodester Class and Exam Timetabling System version 1.0. The flaw exists in the /BSIS.php file, where manipulation of the 'day' argument allows remote attack initiation. As a public exploit exists, updating the affected system is recommended.
Azərbaycanca: Bu CVE SourceCodester-in 1.0 versiyasında Class and Exam Timetabling System-də tapılmış boşluqdur. /BSIS.php faylındakı 'day' arqumenti üzərində manipulyasiya nəticəsində XSS (cross site scripting) zəifliyi yaranır və hücum uzaqdan həyata keçirilə bilər. İctimaiyyətə açıq olan bu istismardan qorunmaq üçün sistemi yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ2
Which system is affected by CVE-2026-16486?
This vulnerability affects version 1.0 of the SourceCodester Class and Exam Timetabling System.
Where does the exploitation of CVE-2026-16486 occur?
The exploitation occurs through manipulation of the 'day' argument in the /BSIS.php file.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.