在 SourceCodester 发布的 Class and Exam Timetabling System 1.0 中检测到一处安全漏洞。该漏洞影响 /BSIT2.php 文件中的某一未知功能。通过操纵参数 course,可导致跨站脚本攻击(XSS)。该漏洞支持远程利用,相关利用代码已公开披露,可供攻击者直接使用。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Class and Exam Timetabling System | 1.0 |
cpe:2.3:a:sourcecodester:class_and_exam_timetabling_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78115 | 5.4 MEDIUM | SourceCodester Class and Exam Timetabling System User Account Update edit_user_account.php |
| CVE-2026-78060 | 4.3 MEDIUM | SourceCodester Stock Management System getOrderReport.php cross site scripting |
| CVE-2026-78059 | 4.3 MEDIUM | SourceCodester Stock Management System printOrder.php cross site scripting |
| CVE-2026-78054 | 4.3 MEDIUM | SourceCodester Class and Exam Timetabling System BSIS1.php cross site scripting |
No comments yet