Impact
The vulnerability resides in SourceCodester Online Examination & Learning Management System 1.0 and targets the file /view.php. Manipulating the ID argument permits an attacker to bypass normal authorization checks, granting unauthorized access to protected content or functionality. The weakness aligns with CWE‑285 (Authorization Bypass Through User‑Controlled Key) and CWE‑639 (Authorization Bypass via Privilege Escalation).
Affected Systems
SourceCodester Online Examination & Learning Management System 1.0 is affected; the vulnerability originates from unknown code within the /view.php module. No other vendors or product versions are listed as impacted.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity for this remote exploit. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog. The attack requires remote access to the web interface and the ability to supply a crafted ID parameter, after which an unauthorized user can view or manipulate restricted data.
OpenCVE Enrichment