Impact
A flaw in the register.php endpoint of the SourceCodester Online Examination & Learning Management System allows an attacker to manipulate the role argument and gain privileges beyond what is intended. This vulnerability is rooted in the failure to enforce correct privilege restrictions, as identified by CWE-266 and CWE-269. The system can be compromised remotely, and an exploit has already been published, making the threat actionable.
Affected Systems
The impact is limited to installations of SourceCodester Online Examination & Learning Management System version 1.0. The vulnerability resides in an internal function of register.php and affects any instance that has not applied the vendor supplied fix.
Risk and Exploitability
With a CVSS score of 6.9 the risk is moderate, while the EPSS score of <1% indicates a very low but non‑zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Remote attackers need only network access to the registration endpoint and can send crafted requests that override the role parameter, triggering improper privilege management.
OpenCVE Enrichment