A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0 and classified as problematic. This affects an unknown part of the file /BSIS.php. Performing a manipulation of the argument day results in cross site scripting.

This vulnerability was named CVE-2026-16486. The attack may be initiated remotely. In addition, an exploit is available.