Junglewise Threat Intelligence

CVE-2026-86276: SourceCodester Syllabus-Aligned Learning Management & Examination System hardcoded credentials and SQL injection

CVE-2026-86276 · Severity: high · CVSS 7.3 · Published 2026-09-07

Technologies: SourceCodester Syllabus-Aligned Learning Management & Examination System. Vendors: SourceCodester.

Executive brief

A Learning Management System used by educational institutions to manage courses, exams, and student records contains multiple security flaws including hardcoded database credentials and SQL injection vulnerabilities. An attacker can exploit these issues remotely to access sensitive student and institutional data, take over user accounts, or manipulate exam records and grades without authentication.

Technical details

The vulnerability comprises multiple attack vectors: (1) hardcoded credentials in db.php that expose database access details; (2) second-order SQL injection in CSV import functionality (import_users.php); (3) SQL injection in multiple GET parameters including manage_subjects.php; and (4) default/hardcoded password patterns in the SQL dump allowing mass account takeover. The flaws are remotely exploitable without authentication. Attackers can extract sensitive data, inject malicious SQL, or hijack accounts using default credentials found in the application files or database schema. No patch information is available in the advisory.

Affected products

  • SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

Timeline

  • 2026-09-07: disclosed

References

Related threats