CVE-2026-16202: SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /CYS.php. This manipulation of the argument course causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Event History
Frequently Asked Questions
What is the CVE-2026-16202 vulnerability?
CVE-2026-16202 is a cross-site scripting vulnerability in the SourceCodester Class and Exam Timetabling System that allows an attacker to manipulate the course argument in the CYS.php file.
What is the severity of CVE-2026-16202?
CVE-2026-16202 has a severity rating of low, with a score of 3.5 on the CVSS scale.
How can I fix the CVE-2026-16202 vulnerability?
To mitigate CVE-2026-16202, ensure proper input validation and encoding to prevent cross-site scripting attacks.
Can CVE-2026-16202 be exploited remotely?
Yes, CVE-2026-16202 can be exploited remotely by an attacker to execute cross-site scripting.
What software is affected by CVE-2026-16202?
CVE-2026-16202 affects the SourceCodester Class and Exam Timetabling System version 1.0.