Executive brief
SourceCodester's Syllabus-Aligned Learning Management & Examination System (CICT Portal) stores sensitive information including database credentials, user passwords, and student data in cleartext within SQL dump files and application code. An attacker with remote network access can extract these credentials and personally identifiable information, potentially gaining unauthorized access to student records, examination data, and the underlying database.
Technical details
The vulnerability is a cleartext storage of sensitive information flaw affecting multiple components: hardcoded database credentials in db.php, plaintext password disclosure in the cict_portal.sql database dump file (line 441), and hardcoded test user credentials in add_user.php. The root cause is the lack of credential encryption and the inclusion of sensitive data in deployment packages. An unauthenticated attacker can download or access the SQL dump file and application source files via the web application, retrieve database credentials directly, and gain direct access to the MySQL database or escalate privileges to the admin account. No authentication or special preconditions are required beyond network access to the application. Patches or configuration changes to remove hardcoded secrets and encrypt credentials are not yet confirmed as released.
Affected products
- SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0
Timeline
- 2026-09-07: disclosed
- other: CVE-2026-86280 assigned