HomeSecuritySourceCodester BSIT2.php: New XSS vulnerability in Class and Exam Timetabling

SourceCodester BSIT2.php: New XSS vulnerability in Class and Exam Timetabling

The SourceCodester BSIT2 version of the Class and Exam Timetabling System contains a new cross-site scripting (XSS), which has been documented as CVE-2026-78055. The issue is located in an admin page and could allow JavaScript code to be executed in a user's browser that opens affected content.

SourceCodester BSIT2 and new XSS vulnerability

The CVE Alert rates the issue at CVSS 4.3, in the Medium category, and states that remote exploitation is possible. No patch or official upgrade guidance has been released by the manufacturer yet.

See also: CVE-2026-19899 SourceCodester: Critical SQL injection in clock system

SourceCodester BSIT2: Where is the vulnerability located?

The vulnerability affects version 1.0 of the Class and Exam Timetabling System, specifically the file /BSIT2.php. The course accepts a value that is returned to the page without adequate checking, validation, or output encoding. As a result, specially crafted content can be interpreted as active code.

The CVE Feed lists the CVSS 3.1 vector as AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N. Simply put, the attack is network-based, does not require prior privileges, but requires a user to interact with the page containing the malicious payload.

The issue is not general to any PHP installation, but to the specific functionality of the Class and Exam Timetabling System. Administrators who have downloaded the project from a third-party source or customized it internally should check if the BSIT2.php file exists and if the course parameter is displayed without safe editing.

Class and Exam Timetabling page with XSS vulnerability

The public report on GitHub describes a test with JavaScript inside the course. The report notes that no login is required for this scenario and that the result is displayed in the browser when the affected page loads. The report title mentions a different file, but its body points to BSIT2.php.

See also: SourceCodester Class Timetabling: SQL Injection vulnerability CVE-2026-14770

What can cause XSS?

XSS does not itself grant access to the server, but executes commands within the victim's browser. If the user has an active session, an attacker can attempt to read unprotected data, change page elements, redirect the user to a malicious website, or perform actions with their privileges .

The impact depends on how the application is developed, user permissions, and cookie settings. The SecNews technical team has not found any evidence that CVE-2026-78055 is being used widely, but the public disclosure means that administrators should not consider the vulnerability theoretical.

In an organization, a teacher or administrator account may have access to more pages and data than a single user. Therefore, the assessment should consider not only whether the test pop-up appears, but also what session, cookies, and data are available in the browser.

XSS vulnerability in SourceCodester BSIT2

See also: CVE-2026-19384 SourceCodester: Serious SQL injection in dating app

Temporary protection measures for SourceCodester BSIT2

Until an official fix is ​​available, administrators should limit the application's exposure to the internet, require access over a trusted network, and monitor logs for unusual values ​​in the course. Disabling non-essential accounts also reduces the attack surface.

The researcher's report recommends input validation, proper encoding before displaying data in HTML, CSP policy, and cookies with HttpOnly and Secure. These measures are not a substitute for an official patch, but they do limit the likelihood of successful script execution until an update is released.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Where possible, SourceCodester BSIT2 should be operated behind access control rather than as an open service on the internet. Changing passwords, terminating active sessions, and looking for suspicious requests after a potential XSS test are useful actions, particularly in facilities hosting real data.

SourceCodester BSIT2 vulnerability remediation

There is no announcement on the SourceCodester page for version 1.0 or a specific fix for CVE-2026-78055 yet. Installers should monitor official updates and test each new version in an isolated environment before implementing it.

Until there is a clear announcement, it is not safe to assume that a simple change to the page address is sufficient. You need to check the code that displays the course price, log failed requests, and confirm that the outputs are encoded according to the HTML context in which they are used.

The new listing is a reminder that even small course management applications can be an entry point for attacks on users. For SourceCodester BSIT2, immediate isolation, monitoring requests, and waiting for a documented update are the safest next steps.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS