Impact
A flaw in the Script of the SourceCodester Online Examination & Learning Management System allows an attacker to manipulate the user_id parameter in /process_lesson.php and bypass upload restrictions. The result is an ability to upload arbitrary files into a web-accessible directory. If the uploaded file contains executable code, the attacker can achieve remote code execution or persist malicious scripts on the server. The weakness corresponds to improper access control and unrestricted file upload (CWE‑284, CWE‑434).
Affected Systems
The affected product is SourceCodester Online Examination & Learning Management System, version 1.0. The vulnerability exists in the file /process_lesson.php and does not appear to affect other modules or versions per the CNA data.
Risk and Exploitability
The CVSS score of 5.3 rates the flaw as moderate, but the EPSS score of less than 1% indicates a low likelihood of exploitation at the current time. The vulnerability is not listed in CISA’s KEV catalog. Attacks can be launched remotely by sending a crafted user_id value to /process_lesson.php; publicly available exploit code demonstrates the feasibility of real‑world attacks, thus the situation requires monitoring until a patch is applied.
OpenCVE Enrichment