Vulnerability Description
A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-1-process_lesson.md
- https://vuldb.com/cve/CVE-2026-14775
- https://vuldb.com/submit/850677
- https://vuldb.com/vuln/376365
- https://vuldb.com/vuln/376365/cti
- https://www.sourcecodester.com/
FAQ
What is CVE-2026-14775?
CVE-2026-14775 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument ...
How severe is CVE-2026-14775?
CVE-2026-14775 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-14775?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.