Description
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Published: 2026-09-07
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw exists in SourceCodester Syllabus‑Aligned Learning Management & Examination System version 1.0 that allows an attacker to craft a malicious request that is accepted as if it came from a legitimate authenticated user. This cross‑site request forgery flaw can be triggered remotely, meaning an attacker only needs to entice a legitimate user to visit a crafted site or click a link. The public availability of an exploitation script indicates that the vulnerability is already in the wild.

Affected Systems

The vulnerability affects SourceCodester’s Syllabus‑Aligned Learning Management & Examination System; the described impacted version is 1.0. No other versions are listed, and a specific function is not named in the advisory.

Risk and Exploitability

The CVSS score of 5.3 classifies the flaw as medium severity. EPSS data is not available, so the precise likelihood of exploitation cannot be quantified, but the existence of a publicly released exploit and the remote attack vector both raise concern. The vulnerability is not listed in CISA KEV at this time, though that status could change as the threat matures.

Generated by OpenCVE AI on September 7, 2026 at 08:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s official patch or upgrade to the latest release of the Syllabus‑Aligned Learning Management & Examination System
  • Verify that all state‐changing requests include anti‑CSRF tokens and enforce server‑side validation of those tokens
  • Configure session cookies with the SameSite attribute and consider additional CSRF protection frameworks such as double submit cookies or synchronizer tokens

Generated by OpenCVE AI on September 7, 2026 at 08:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Title SourceCodester Syllabus-Aligned Learning Management & Examination System cross-site request forgery
First Time appeared Sourcecodester
Sourcecodester syllabus-aligned Learning Management Examination System
Weaknesses CWE-352
CWE-862
CPEs cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_examination_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester syllabus-aligned Learning Management Examination System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:N/I:P/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Syllabus-aligned Learning Management Examination System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-07T07:30:11.038Z

Reserved: 2026-09-06T13:34:01.191Z

Link: CVE-2026-86281

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-07T08:17:14.380

Modified: 2026-09-07T08:17:14.380

Link: CVE-2026-86281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-07T08:30:14Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)

  • CWE-862

    Missing Authorization