CVE-2026-1154: SourceCodester E-Learning System Lesson index.php cross site scripting
A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-1154?
CVE-2026-1154 has been categorized as a moderate severity vulnerability due to its potential for cross-site scripting exploitation.
How do I fix CVE-2026-1154?
To mitigate CVE-2026-1154, sanitize and validate user inputs in the Title parameter of the Lesson Module Handler.
What systems are affected by CVE-2026-1154?
CVE-2026-1154 affects SourceCodester E-Learning System version 1.0 specifically.
What kind of attack can CVE-2026-1154 lead to?
CVE-2026-1154 can lead to cross-site scripting attacks allowing an attacker to inject malicious scripts into web pages.
Is there a fix available for CVE-2026-1154?
As of now, a specific patch for CVE-2026-1154 has yet to be released, so manual input validation is recommended.