Onlne Examination Learning Management System Sourcecodester Onlne Examination Learning Management System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Sourcecodester Onlne Examination Learning Management System.

By the Year

In 2026 there have been 6 vulnerabilities in Sourcecodester Onlne Examination Learning Management System with an average score of 6.5 out of ten.

Year Vulnerabilities Average Score
2026 6 6.47

It may take a day or so for new Onlne Examination Learning Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Sourcecodester Onlne Examination Learning Management System Security Vulnerabilities

Improper Auth in SourceCodester OnlineExam LMS 1.0 via /ajax_enroll.php
CVE-2026-14778 7.3 - High - July 05, 2026

A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajax_enroll.php of the component Enrollment Management. The manipulation of the argument student_id/schedule_id/action leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The name of the affected product appears to have a typo in it.

AuthZ

SourceCodester Onlne LMS 1.0 Unrestricted File Upload via /announcements.php
CVE-2026-14777 6.3 - Medium - July 05, 2026

A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The name of the affected product appears to have a typo in it.

Unrestricted File Upload

Unrestricted Upload via pathinfo in SourceCodester Onlne LMS 1.0 (FilenameExt)
CVE-2026-14776 6.3 - Medium - July 05, 2026

A security flaw has been discovered in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this vulnerability is the function pathinfo of the file /upload_files.php of the component Filename Extension. Performing a manipulation results in unrestricted upload. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The name of the affected product appears to have a typo in it.

Unrestricted File Upload

SourceCodester Exam LMS 1.0 - Unrestricted Upload (user_id)
CVE-2026-14775 6.3 - Medium - July 05, 2026

A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.

Unrestricted File Upload

SourceCodester Onlne Exam LMS 1.0 Remote Role Manipulation in register.php
CVE-2026-14719 7.3 - High - July 05, 2026

A flaw has been found in SourceCodester Onlne Examination & Learning Management System 1.0. The impacted element is an unknown function of the file register.php of the component Registration Endpoint. Executing a manipulation of the argument role can lead to improper privilege management. The attack can be executed remotely. The exploit has been published and may be used. The name of the affected product appears to have a typo in it.

Improper Privilege Management

Hardcoded password via raw_password in import_users.php (SourceCodester OLE LMS)
CVE-2026-11552 5.3 - Medium - June 08, 2026

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password with the input CICT_2026 leads to use of hard-coded password. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. This product is distributed under two entirely different names.

Use of Hard-coded Password

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Sourcecodester Onlne Examination Learning Management System or by Sourcecodester? Click the Watch button to subscribe.

subscribe