SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-90615

MEDIUM · CVSS 4.3 EPSS 0.27% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A cross-site scripting vulnerability exists in the SourceCodester Class and Exam Timetabling System 1.0, specifically affecting the /subject1.php file, where manipulation of the 'subject' argument can allow remote attackers to execute scripts in the context of the user's browser. Organizations using this system should prioritize remediation efforts to mitigate potential exploitation, especially those handling sensitive user data or operating in educational environments.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-90615
Severity
MEDIUM
CVSS
4.3
EPSS
0.27%

Original NVD Description

A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /subject1.php. Such manipulation of the argument subject leads to cross site scripting. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.