← Back to overview

A vulnerability has been identified in SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0. The flaw resides in the file db.php, where improper handling leads to hard-coded credentials being exposed. This vulnerability can be exploited remotely by attackers without requiring physical access to the system. The exploit has been publicly disclosed and is available for use, increasing the risk of active exploitation. Hard-coded credentials typically allow unauthorized access to backend systems, including databases. The issue is classified as a high-severity vulnerability due to its remote exploitability and public exploit availability. Organizations using this LMS platform are advised to apply patches or mitigations immediately. The vulnerability was reported via VulDB and is tracked under CVE-2026-86276.

Affected products

  • SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0

Related CVE's

  • CVE-2026-86276

Categories

  • Database & Storage
  • Identity & Access
  • Web Technologies