Description
A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Published: 2026-04-05
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Credential Exposure
Action: Patch
AI Analysis

Impact

An HTTP GET request handler in SourceCodester Student Result Management System version 1.0 writes login credentials to /login_credentials.txt in cleartext when the request is processed. The flaw allows attackers to obtain valid usernames and passwords from the file, compromising the confidentiality of user accounts. The weakness is a classic privilege and data exposure issue, evidenced by the assignment of CWE‑312 and CWE‑313.

Affected Systems

The only affected product is SourceCodester Student Result Management System 1.0, which stores credentials on disk during a GET request. No other vendors, products, or versions are listed as impacted.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating moderate to high risk. No publicly available exploitation probability score is available, and the issue is not listed in the CISA KEV catalog. Attackers can trigger the vulnerability remotely via a crafted HTTP GET request, reading the stored cleartext credentials and potentially gaining unauthorized access to user accounts.

Generated by OpenCVE AI on April 5, 2026 at 04:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or update for SourceCodester Student Result Management System
  • Restrict or disable the GET endpoint that writes /login_credentials.txt until a fix is available
  • Configure the system to store credentials securely by hashing or encrypting them
  • Monitor web server logs for unauthorized access attempts to the vulnerable endpoint

Generated by OpenCVE AI on April 5, 2026 at 04:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester student Result Management System
Vendors & Products Sourcecodester
Sourcecodester student Result Management System

Mon, 06 Apr 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 05 Apr 2026 02:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Student Result Management System 1.0. Impacted is an unknown function of the file /login_credentials.txt of the component HTTP GET Request Handler. The manipulation leads to cleartext storage in a file or on disk. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.
Title SourceCodester Student Result Management System HTTP GET Request login_credentials.txt cleartext storage in file
Weaknesses CWE-312
CWE-313
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:W/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:W/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Student Result Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-06T14:51:24.567Z

Reserved: 2026-04-04T06:31:14.683Z

Link: CVE-2026-5531

cve-icon Vulnrichment

Updated: 2026-04-06T14:04:33.955Z

cve-icon NVD

Status : Deferred

Published: 2026-04-05T02:16:00.130

Modified: 2026-04-24T18:13:28.877

Link: CVE-2026-5531

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-06T21:57:23Z

Weaknesses