Junglewise Threat Intelligence

CVE-2026-11552: SourceCodester Online Examination & Learning Management System hard-coded password in import_users.php

CVE-2026-11552 · Severity: medium · CVSS 5.3 · Published 2026-06-08

Technologies: SourceCodester Online Examination & Learning Management System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Examination & Learning Management System. The software contains a hard-coded password within its user import functionality, which could allow an unauthorized person to gain access to the system. This could lead to the exposure of student or examination data and compromise the integrity of the learning platform.

Technical details

A vulnerability classified as CWE-259 (Use of Hard-coded Password) exists in SourceCodester Online Examination & Learning Management System 1.0 (also distributed as Syllabus-aligned Learning Management and Examination System). The issue is located in the 'import_users.php' file, where the 'raw_password' argument is manipulated using a hard-coded value ('CICT_2026'). A remote attacker can exploit this to bypass intended credential management or predict user passwords during the import process. The exploit has been disclosed publicly, increasing the risk of unauthorized access. No official patch has been confirmed at this time.

Affected products

  • SourceCodester Onlne Examination & Learning Management System 1.0
  • SourceCodester Syllabus-aligned Learning Management and Examination System 1.0

Timeline

  • 2026-06-08: disclosed: Exploit disclosed to the public
  • 2026-06-08: advisory: CVE published by NVD/VulDB

References

Related threats