Junglewise Threat Intelligence

CVE-2026-14776: SourceCodester Online Examination & Learning Management System unrestricted upload in upload_files.php

CVE-2026-14776 · Severity: medium · CVSS 6.3 · Published 2026-07-05

Technologies: SourceCodester Online Examination & Learning Management System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Examination & Learning Management System, a platform used for managing educational content and testing. An attacker can bypass file upload restrictions to place unauthorized files on the server. This could allow an attacker to disrupt services, access sensitive data, or potentially take control of the web server.

Technical details

An unrestricted file upload vulnerability exists in SourceCodester Online Examination & Learning Management System 1.0. The flaw is located in the 'pathinfo' function within the '/upload_files.php' file, which fails to properly validate or sanitize filename extensions. A remote attacker with low privileges can manipulate the upload process to bypass extension checks and upload arbitrary files. This can lead to remote code execution (RCE) if the uploaded files are executable by the server. Public exploit code has been released for this vulnerability.

Affected products

  • SourceCodester Onlne Examination & Learning Management System 1.0

Timeline

  • 2026-07-05: disclosed
  • 2026-07-05: advisory

References

Related threats