Impact
The vulnerability is a cross‑site request forgery that allows a remote attacker to trick a user into submitting state‑changing requests through an unprotected functionality in SourceCodester Onlne Examination & Learning Management System 1.0. The flaw resides in missing CSRF protection, enabling an attacker to force the victim to perform actions such as modifying data or changing settings without the victim’s consent. This weakness does not provide object‑level access control, so the impact is limited to the permissions of the authenticated user whose browser is exploited.
Affected Systems
SourceCodester Onlne Examination & Learning Management System, version 1.0. No other versions or products are listed as affected.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity vulnerability. No EPSS score is available, and the vulnerability is not listed in CISA KEV. The attack can be launched remotely, and the attacker requires only the ability to initiate a request from a victim’s browser. The absence of a known exploit in public channels suggests the risk is primarily theoretical, but the remote nature and lack of user authentication for the request make it a potentially actionable threat.
OpenCVE Enrichment