Junglewise Threat Intelligence

CVE-2026-14775: SourceCodester Online Examination & Learning Management System unrestricted upload in process_lesson.php

CVE-2026-14775 · Severity: medium · CVSS 6.3 · Published 2026-07-05

Technologies: SourceCodester Online Examination & Learning Management System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Examination & Learning Management System, a platform used for managing educational content and testing. An attacker can exploit a flaw in the lesson processing component to upload unauthorized files to the server. This could allow an attacker to gain control over the system, potentially leading to data theft or service disruption.

Technical details

An unrestricted file upload vulnerability (CWE-434) exists in SourceCodester Online Examination & Learning Management System 1.0 within the '/process_lesson.php' file. The vulnerability is triggered by manipulating the 'user_id' argument, which lacks proper access control and validation. A remote attacker with low privileges can exploit this to upload arbitrary files to the web server. This can lead to remote code execution (RCE) if the attacker uploads a malicious script (e.g., a PHP shell). Public exploit code is reportedly available.

Affected products

  • SourceCodester Onlne Examination & Learning Management System 1.0

Timeline

  • 2026-07-05: advisory: NVD publication date

References

Related threats