在 SourceCodester 的“与教学大纲对齐的学习管理与考试系统 1.0”中发现了一个漏洞。该漏洞影响 auth.php 文件中的 register 函数。对参数 role 进行操作会导致权限管理不当。该漏洞可被远程利用,且该漏洞利用方式已公开,可能被使用。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | Syllabus-Aligned Learning Management & Examination System | 1.0 |
cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_examination_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-86292 | 7.3 HIGH | SourceCodester Simple Traffic Offense System User Creation saveuser.php missing authentica |
| CVE-2026-86290 | 7.3 HIGH | SourceCodester Online Voting System ajax.php save_category sql injection |
| CVE-2026-86277 | 7.3 HIGH | SourceCodester Syllabus-Aligned Learning Management & Examination System delete_exam.php a |
| CVE-2026-86276 | 7.3 HIGH | SourceCodester Syllabus-Aligned Learning Management & Examination System db.php hard-coded |
| CVE-2026-86293 | 6.5 MEDIUM | SourceCodester Simple Traffic Offense System Deletion Endpoint delete-user.php missing aut |
| CVE-2026-86279 | 6.3 MEDIUM | SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_proces |
| CVE-2026-86280 | 5.3 MEDIUM | SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql c |
| CVE-2026-86281 | 4.3 MEDIUM | SourceCodester Syllabus-Aligned Learning Management & Examination System cross-site reques |
| CVE-2026-86278 | 4.3 MEDIUM | SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.p |
No comments yet