CVE-2026-86279: SourceCodester Syllabus-Aligned Learning Management & Examination System Login auth_process.php session fixiation
A vulnerability was determined in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. The impacted element is an unknown function of the file authprocess.php of the component Login. This manipulation causes session fixiation. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the Login/auth_process.php endpoint from untrusted networks (e.g., block or limit inbound access at the firewall/ACL) until the session fixiation issue is remediated.
Event History
Frequently Asked Questions
Which deployments should be considered exposed?
SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0 is identified as affected. The issue is reachable remotely through the Login component.
What does exploitation require?
The supplied severity vector indicates network access, low attack complexity, no privileges, and user interaction. Public exploit disclosure means exploit code or techniques may be available to attackers.