Junglewise Threat Intelligence

CVE-2026-14719: SourceCodester Online Examination & LMS privilege escalation in registration endpoint

CVE-2026-14719 · Severity: high · CVSS 7.3 · Published 2026-07-05

Technologies: SourceCodester Online Examination & Learning Management System. Vendors: SourceCodester.

Executive brief

A security flaw exists in the SourceCodester Online Examination & Learning Management System, a platform used for managing educational content and exams. An unauthorized user can manipulate the registration process to grant themselves administrative privileges. This allows an attacker to gain full control over the system, including access to student personal information, exam results, and the ability to modify grades or enrollment records.

Technical details

An improper privilege management vulnerability (CWE-269) exists in the registration endpoint of SourceCodester Online Examination & Learning Management System 1.0. The file `auth_process.php` accepts a `role` parameter directly from a POST request without server-side validation or restriction. While the `register.php` frontend only presents 'Student' and 'Instructor' options in a dropdown, an attacker can bypass the UI and submit a POST request with `role=super_admin`. This results in the creation of a new account with full administrative privileges. A public exploit (PoC) is available, and the vulnerability can be exploited remotely without prior authentication.

Affected products

  • SourceCodester Online Examination & Learning Management System 1.0

Timeline

  • 2026-06-04: disclosed: Public PoC published on Pastebin
  • 2026-07-05: advisory: NVD/VulDB advisory published

References

Related threats