A vulnerability, which was classified as problematic, was found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /class.php. Such manipulation of the argument day leads to cross site scripting.

This vulnerability is uniquely identified as CVE-2026-16485. The attack can be launched remotely. Moreover, an exploit is present.