CVE-2026-86276 Details
Description
A flaw has been found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used.
A vulnerability exists in SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0, specifically within the file db.php. This flaw allows for the extraction of hard-coded database credentials, which can lead to unauthorized database access. The vulnerability can be exploited remotely, and the associated exploit has been made public.
To address this vulnerability, remove hard-coded credentials from the db.php file and replace them with environment variables. Ensure that the MySQL root account has a strong password and create a limited-privilege application user for database operations.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 7, 2026CISA-ADP
Assessed Sep 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-03-SQL-Injection-Hardcoded-Credentials.md | [email protected] | BundleExploitRemedyTechnical Analysis |
| https://vuldb.com/cve/CVE-2026-86276 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/904873 | [email protected] | Permission Required |
| https://vuldb.com/vuln/399437 | [email protected] | Permission Required |
| https://vuldb.com/vuln/399437/cti | [email protected] | Content Wall |
| https://www.sourcecodester.com/ | [email protected] | Vendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-259 | Use of Hard-coded Password | [email protected] |
| CWE-798 | Use of Hard-coded Credentials | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| SourceCodester Syllabus-Aligned Learning Management & Examination System | 1.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 9, 2026 | CVE Modified | CISA-ADP |
| Sep 7, 2026 | New CVE Received | [email protected] |
Volerion