CVE-2026-14775 MEDIUM

CVE-2026-14775: SourceCodester Onlne Examination & Learning Management System process_lesson.php unrestricted upload

Vendor Sourcecodester
Product Onlne Examination & Learning Management System
Weakness CWE-434 · Unrestricted file upload
Published July 5, 2026
Last update July 7, 2026

CVSS base score

5.3/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P

What the vulnerability does

01Description

A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.

Key dates

02Disclosure timeline

July 5, 2026 CVE published
July 7, 2026 Record updated

Related vulnerabilities

04Related CVE