Executive brief
Campcodes Complete Online Learning Management System, a platform used for managing educational content and student lessons, contains a security flaw in its lesson creation feature. An attacker can exploit this to upload unauthorized files to the server. This could lead to a disruption of educational services, unauthorized access to system data, or a complete takeover of the web server hosting the platform.
Technical details
An unrestricted file upload vulnerability exists in Campcodes Complete Online Learning Management System 1.0 within the add_lesson function of the /application/models/Crud_model.php component. The application fails to properly validate file extensions or content types during the lesson creation process. A remote attacker with low-level privileges (such as a teacher or instructor account) can exploit this flaw to upload malicious scripts, such as a PHP web shell, to the server. Successful exploitation allows for arbitrary code execution in the context of the web server. A public exploit has been reported for this vulnerability.
Affected products
- Campcodes Complete Online Learning Management System 1.0
Timeline
- 2026-04-05: disclosed
- 2026-04-05: advisory