CVE-2026-14778: SourceCodester Onlne Examination & Learning Management System Enrollment Management ajax_enroll.php improper authorization
A security vulnerability has been detected in SourceCodester Onlne Examination & Learning Management System 1.0. This affects an unknown part of the file /ajaxenroll.php of the component Enrollment Management. The manipulation of the argument studentid/scheduleid/action leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The name of the affected product appears to have a typo in it.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-14778?
The severity of CVE-2026-14778 is rated high at 7.3.
How do I fix CVE-2026-14778?
To fix CVE-2026-14778, ensure proper authorization checks are implemented in the ajax_enroll.php file.
What component is affected by CVE-2026-14778?
CVE-2026-14778 affects the Enrollment Management component of the SourceCodester Online Examination & Learning Management System.
What type of vulnerability is CVE-2026-14778?
CVE-2026-14778 is an improper authorization vulnerability.
What arguments are manipulated in CVE-2026-14778?
CVE-2026-14778 involves the manipulation of the arguments student_id, schedule_id, and action.