Executive brief
A security vulnerability exists in the SourceCodester Online Examination & Learning Management System, a platform used for managing educational content and exams. An attacker can exploit this flaw to upload unauthorized files to the server. This could allow a malicious actor to gain control over the system, potentially leading to data theft or a complete service disruption.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in SourceCodester Online Examination & Learning Management System 1.0 within the 'announcements.php' file. The application fails to properly validate file types or permissions during the upload process. A remote attacker with low-level privileges can exploit this by uploading a malicious script (such as a PHP shell) to the server. Successful exploitation allows for remote code execution (RCE) on the underlying host. A public exploit has been disclosed, increasing the risk of active exploitation.
Affected products
- SourceCodester Online Examination & Learning Management System 1.0
Timeline
- 2026-07-06: advisory: Vulnerability published in NVD and VulDB