在 SourceCodester 班级与考试日程安排系统 1.0 中发现了一个弱点。受影响的文件 /BSIS1.php 中存在一个未知函数。通过对 course 参数进行操控,可导致跨站脚本攻击(XSS)。该攻击可以远程发起。相关利用代码已公开,可能被用于实施攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78115 | 5.4 MEDIUM | SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php |
| CVE-2026-78060 | 4.3 MEDIUM | SourceCodester Stock Management System getOrderReport.php cross site scripting |
| CVE-2026-78059 | 4.3 MEDIUM | SourceCodester Stock Management System printOrder.php cross site scripting |
| CVE-2026-78055 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System BSIT2.php cross site scripting |
No comments yet