Junglewise Threat Intelligence

CVE-2026-14778: SourceCodester Online Examination & Learning Management System improper authorization in ajax_enroll.php

CVE-2026-14778 · Severity: high · CVSS 7.3 · Published 2026-07-06

Technologies: SourceCodester Online Examination & Learning Management System. Vendors: SourceCodester.

Executive brief

A security vulnerability exists in the SourceCodester Online Examination & Learning Management System version 1.0. This flaw allows unauthorized individuals to potentially access or modify enrollment data remotely. Such an exploit could compromise student records, disrupt educational operations, and lead to unauthorized changes in course schedules or student enrollments.

Technical details

An Insecure Direct Object Reference (IDOR) or improper authorization vulnerability exists in SourceCodester Online Examination & Learning Management System 1.0. The flaw is located in the Enrollment Management component, specifically within the /ajax_enroll.php file. By manipulating the student_id, schedule_id, or action parameters, a remote attacker can bypass authorization checks. This allows for unauthorized actions related to student enrollments without proper authentication. The exploit has been publicly disclosed, though no official patch is currently confirmed.

Affected products

  • SourceCodester Online Examination & Learning Management System 1.0

Timeline

  • 2026-07-06: advisory: NVD publication date
  • 2026-07-05: disclosed: Public disclosure of the exploit via GitHub and VulDB

References

Related threats