Impact
The vulnerability resides in the db.php file of the SourceCodester Syllabus‑Aligned Learning Management & Examination System 1.0 and contains hard‑coded credentials that can be accessed through remote input manipulation. Attackers can bypass authentication and potentially gain unrestricted access to the system’s administrative functions, leveraging weaknesses of insecure credential storage (CWE‑259, CWE‑798).
Affected Systems
Only the SourceCodester Syllabus‑Aligned Learning Management & Examination System, version 1.0, is affected. No other versions or products have been identified as vulnerable.
Risk and Exploitability
The CVSS score is 6.9, indicating a moderate‑to‑high severity. EPSS is not available, and while the exploit is published, there is no confirmation of real‑world exploitation, meaning the threat remains theoretical. It is not listed in the CISA KEV catalog. Attackers can execute this remotely by providing specially crafted input to db.php, triggering the embedded credentials.
OpenCVE Enrichment