Description
A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Published: 2026-09-07
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Apply Fix
AI Analysis

Impact

Manipulation of an unknown function within the file cict_portal.sql causes sensitive information to be stored in plain text, exposing data that should remain confidential. This flaw enables an attacker to gain read access to credentials and other private details that the system processes, potentially leading to credential compromise and further exploitation. The vulnerability is classified as a moderate-severity disclosure, reflecting its impact on data confidentiality.

Affected Systems

SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0 is affected. The flaw resides in the database script cict_portal.sql, which handles data storage for the application. No other versions or components are confirmed affected at this time.

Risk and Exploitability

With a CVSS score of 6.9, the vulnerability presents a moderate risk. The exploit is available publicly and can be launched remotely, though the EPSS score is currently not provided. Because it is not listed in the CISA KEV catalog, the likelihood of widespread exploitation is unknown, yet the remote nature of the attack vector and the cleartext storage compromise makes it a significant security concern.

Generated by OpenCVE AI on September 7, 2026 at 08:50 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact SourceCodester to obtain an update that protects sensitive data in the database script.
  • If a patch is not immediately available, reconfigure the database to store these fields encrypted or hashed.
  • Apply database access controls to restrict read permissions to only trusted application components.

Generated by OpenCVE AI on September 7, 2026 at 08:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 08 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 07 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was identified in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This affects an unknown function of the file cict_portal.sql. Such manipulation leads to cleartext storage of sensitive information. It is possible to launch the attack remotely. The exploit is publicly available and might be used.
Title SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
First Time appeared Sourcecodester
Sourcecodester syllabus-aligned Learning Management Examination System
Weaknesses CWE-310
CWE-312
CPEs cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_examination_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester syllabus-aligned Learning Management Examination System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Syllabus-aligned Learning Management Examination System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-08T13:41:56.231Z

Reserved: 2026-09-06T13:33:57.650Z

Link: CVE-2026-86280

cve-icon Vulnrichment

Updated: 2026-09-08T13:41:53.048Z

cve-icon NVD

Status : Deferred

Published: 2026-09-07T08:17:13.897

Modified: 2026-09-08T14:17:33.740

Link: CVE-2026-86280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T13:17:47Z

Weaknesses