CVE-2026-14719

7.3

SourceCodester · Online Examination & Learning Management System

A privilege management vulnerability in SourceCodester's Online Examination & Learning Management System 1.0 allows for potential unauthorized access.

Executive summary

A critical privilege management flaw in SourceCodester's Online Examination & Learning Management System could allow unauthenticated attackers to gain unauthorized access.

Vulnerability

The application suffers from improper privilege management and incorrect privilege assignment (CWE-269/CWE-266). This vulnerability allows attackers to bypass intended access controls and escalate privileges within the system without authentication.

Business impact

With a CVSS score of 7.3, this vulnerability represents a significant threat to data privacy and system integrity. Unauthorized access to an examination and learning management system can lead to the compromise of sensitive user data, alteration of examination results, and unauthorized administrative control over the platform.

Remediation

Immediate Action: Contact the vendor or monitor the official SourceCodester website for security patches addressing privilege management flaws in version 1.0.

Proactive Monitoring: Inspect application access logs for unusual administrative activity or unauthorized access attempts to restricted modules.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to detect and block suspicious access patterns or unauthorized attempts to reach administrative endpoints.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Due to the ease of exploitation, immediate attention is required. Administrators should restrict external access to the application until a patch is applied and verify all current user privilege assignments to ensure no unauthorized accounts have been created.

More SourceCodester CVEs