CVE-2026-86281: SourceCodester Syllabus-Aligned Learning Management & Examination System cross-site request forgery
A security flaw has been discovered in SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0. This impacts an unknown function. Performing a manipulation results in cross-site request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments of SourceCodester Syllabus-Aligned Learning Management & Examination System version 1.0 are identified as affected. The attack can be initiated remotely and requires user interaction.
What does an attacker need to exploit it?
No attacker privileges are required, but exploitation requires interaction from a user. The vulnerability is classified as cross-site request forgery, meaning the available data indicates a request-manipulation attack rather than direct unauthenticated modification.
Is public exploit information available?
Yes. The exploit has been released publicly and may be used in attacks.