What is CVE-2026-75078?
A remote cross-site scripting (XSS) vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0, affecting the `/BSHRM1.php` file via manipulation of the `course` argument. Immediate input sanitization and filtering are required.
Azərbaycanca: SourceCodester Class and Exam Timetabling System 1.0-da `/BSHRM1.php` faylında `course` parametrinin manipulyasiyası ilə uzaqdan cross-site scripting (XSS) zəifliyi aşkarlanıb. Təcili olaraq daxil edilən məlumatların filtrasiyası tətbiq edilməlidir.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: SourceCodester
FAQ2
Which file in SourceCodester Class and Exam Timetabling System 1.0 is vulnerable to XSS?
The vulnerability exists in the `/BSHRM1.php` file.
Which parameter is manipulated to exploit CVE-2026-75078?
The `course` parameter is manipulated.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.