CVE-2026-86278: SourceCodester Syllabus-Aligned Learning Management & Examination System manage_subjects.php cross site scripting
Published Sep 7, 2026
·Updated
A vulnerability was found in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The affected element is an unknown function of the file managesubjects.php. The manipulation of the argument msg/title/content results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used.
Affected Software
1 affected component
Sourcecodester Syllabus-Aligned Learning Management & Examination System=1.0
Event History
Sep 7, 2026
CVE Published
via MITRE·06:45 AM
Data Sourced
via MITRE·06:45 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:16 AM
DescriptionSeverityWeakness
Nov 27, 58653
Event
via NVD·03:34 AM
Frequently Asked Questions
1
Does exploitation require an authenticated account or direct access to the application host?
No privileges are required, and the attack can be performed remotely. Successful exploitation does require user interaction.
2
Which inputs should be prioritized when assessing exposure?
The affected file is manage_subjects.php, with the msg, title, and content arguments identified as injection points. The affected product version named in the available data is 1.0.
3
Is exploit code available?
Yes. The exploit has been made public and could be used.