Impact
A session fixation vulnerability exists in the auth_process.php component of SourceCodester Syllabus-Aligned Learning Management & Examination System. The flaw originates from an unknown function that allows an attacker to set a predetermined session identifier during the authentication process, thereby enabling the hijacking of a legitimately authenticated session. Because the issue can be triggered remotely and the exploit has been publicly disclosed, an attacker can force a victim's session ID to a value under the attacker's control, potentially accessing the victim's account without legitimate credentials.
Affected Systems
The affected product is SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0. No other versions are documented as impacted.
Risk and Exploitability
The CVSS v3.1 score of 5.3 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from the available data. The vulnerability is not listed in the CISA KEV catalog, but the publicly disclosed exploit and remote initiation capability suggest that attackers could target the system. With session fixation, the attacker could gain unauthorized access to user accounts or sensitive data if session regeneration is not performed immediately after login.
OpenCVE Enrichment