Impact
A flaw exists in SourceCodester Syllabus‑Aligned Learning Management & Examination System version 1.0 that allows an attacker to craft a malicious request that is accepted as if it came from a legitimate authenticated user. This cross‑site request forgery flaw can be triggered remotely, meaning an attacker only needs to entice a legitimate user to visit a crafted site or click a link. The public availability of an exploitation script indicates that the vulnerability is already in the wild.
Affected Systems
The vulnerability affects SourceCodester’s Syllabus‑Aligned Learning Management & Examination System; the described impacted version is 1.0. No other versions are listed, and a specific function is not named in the advisory.
Risk and Exploitability
The CVSS score of 5.3 classifies the flaw as medium severity. EPSS data is not available, so the precise likelihood of exploitation cannot be quantified, but the existence of a publicly released exploit and the remote attack vector both raise concern. The vulnerability is not listed in CISA KEV at this time, though that status could change as the threat matures.
OpenCVE Enrichment