CVE-2026-14775 Details
Description
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.
A critical unrestricted file upload vulnerability has been identified in SourceCodester Online Examination & Learning Management System version 1.0. The issue resides in the file '/process_lesson.php', where an unknown function allows authenticated users to upload files without proper validation. The vulnerability can be exploited remotely, with public proof-of-concept available.
Users are advised to implement an extension whitelist, add role enforcement checks, disable PHP execution in upload directories, store files with non-executable extensions, and implement CSRF protection.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 5, 2026CISA-ADP
Assessed Jul 7, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-1-process_lesson.md | [email protected] | ExploitTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-14775 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/850677 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/376365 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/376365/cti | [email protected] | AdvisoryPermission Required |
| https://www.sourcecodester.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | [email protected] |
| CWE-434 | Unrestricted Upload of File with Dangerous Type | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SourceCodester Online Examination & Learning Management System | v1.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 7, 2026 | CVE Modified | CISA-ADP |
| Jul 5, 2026 | New CVE Received | [email protected] |
Volerion