Unrestricted File Upload Vulnerability in SourceCodester Online Examination System
CVE-2026-19065
5.3MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 6 August 2026
What is CVE-2026-19065?
A vulnerability exists in the SourceCodester Online Examination & Learning Management System 1.0, specifically in the processing of the upload_files.php file. This flaw permits attackers to exploit unrestricted file upload capabilities, allowing them to potentially upload malicious files. These actions can be initiated remotely, leading to further security risks such as remote code execution or data breaches. Proper security measures and updates are essential to mitigate the risks associated with this vulnerability.
Affected Version(s)
Online Examination & Learning Management System 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Adnan (VulDB User)
VulDB Vulnerability Moderation Team
