CVE-2026-14775: Unrestricted Upload in SourceCodester Onlne Examination & Learning Management System
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.
AI Analysis
Technical Summary
This vulnerability affects SourceCodester Onlne Examination & Learning Management System 1.0. An attacker can exploit an unrestricted upload flaw by manipulating the user_id parameter in the /process_lesson.php script. This allows remote attackers to upload files without proper restrictions. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. There is no vendor advisory or patch available at this time, and the exploit code is publicly available.
Potential Impact
Successful exploitation allows remote attackers to upload files without restriction, potentially leading to unauthorized file placement on the server. This could facilitate further attacks such as code execution or defacement depending on server configuration and file handling. The vulnerability requires low attack complexity and no user interaction, but some privileges are needed (PR:L).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the affected script and validate or sanitize user inputs related to file uploads. Implement web application firewall rules to detect and block malicious upload attempts.
CVE-2026-14775: Unrestricted Upload in SourceCodester Onlne Examination & Learning Management System
Description
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.
CVSS v4.0
Score 5.3medium
Affected software
cpe:2.3:a:sourcecodester:onlne_examination_learning_management_system:*:*:*:*:*:*:*:*AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability affects SourceCodester Onlne Examination & Learning Management System 1.0. An attacker can exploit an unrestricted upload flaw by manipulating the user_id parameter in the /process_lesson.php script. This allows remote attackers to upload files without proper restrictions. The vulnerability has a CVSS 4.0 base score of 5.3, indicating medium severity. There is no vendor advisory or patch available at this time, and the exploit code is publicly available.
Potential Impact
Successful exploitation allows remote attackers to upload files without restriction, potentially leading to unauthorized file placement on the server. This could facilitate further attacks such as code execution or defacement depending on server configuration and file handling. The vulnerability requires low attack complexity and no user interaction, but some privileges are needed (PR:L).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is released, restrict access to the affected script and validate or sanitize user inputs related to file uploads. Implement web application firewall rules to detect and block malicious upload attempts.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-07-05T04:08:13.179Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a4ae38827e9c79719facc41
Added to database: 07/05/2026, 23:06:48 UTC
Last enriched: 07/13/2026, 08:51:05 UTC
Last updated: 08/19/2026, 22:52:10 UTC
Views: 107
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.