Executive brief
SourceCodester's Syllabus-Aligned Learning Management & Examination System is a web-based platform used for educational institutions to manage coursework and exams. The system contains multiple cross-site scripting vulnerabilities that allow attackers to inject malicious scripts through various parameters (msg, title, content) and stored fields (announcements, lesson slides). Attackers can steal user session cookies, hijack accounts, or display fake content to students and instructors without any authentication required.
Technical details
The vulnerability is a combination of reflected and stored cross-site scripting (XSS) in the manage_subjects.php file and other application pages. The root cause is insufficient input validation and output encoding of user-supplied parameters including msg, title, and content fields. Attack vectors include reflected XSS via GET parameters (msg), stored XSS through announcements and lesson slide content storage, and error-based XSS via SQL error messages. The attack is remotely exploitable and requires no prior authentication. An attacker can execute arbitrary JavaScript in the context of a logged-in user's session, leading to session hijacking, credential theft, and malware distribution. Patches with proper input validation and output encoding are recommended.
Affected products
- SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0
Timeline
- 2026-09-07: disclosed
- other: Exploit made public