Sceawere

Vulnerability Detail

CVE-2026-19064UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Authorization Bypass in Online Examination

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.3
Creation Date
1d ago
Vendor
SourceCodester
Product
Online Examination & Learning Management System
Attack Type
Authorization Bypass
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was found in SourceCodester Online Examination & Learning Management System 1.0. This vulnerability affects unknown code of the file /view.php. The manipulation of the argument ID results in authorization bypass. The attack can be launched remotely.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.3",
  "pubDate": "2026-08-06T22:16:53.603Z",
  "pubdate": "2026-08-06T22:16:53.603Z",
  "executiveSummary": "An authorization bypass vulnerability has been identified within SourceCodester Online Examination & Learning Management System 1.0. This security flaw resides in the processing logic of the /view.php file when handling user-supplied input via the ID parameter.\nThe vulnerability class is categorized as an authorization bypass, allowing remote attackers to circumvent access control mechanisms and interact with restricted resources or functionality without proper validation.\nThe impact of successful exploitation includes unauthorized data access and potential exposure of sensitive application content meant to be restricted to privileged roles.\nThe affected system is SourceCodester Online Examination & Learning Management System version 1.0, specifically impacting the unknown code executing within /view.php.\nRisk implications are moderate to high, as the vulnerability is remotely exploitable over the network without requiring complex preconditions, lowering the barrier of entry for malicious actors.\nAttacker capabilities involve remote execution of HTTP requests targeting the vulnerable endpoint, manipulating parameter values to subvert access checks, and retrieving restricted application states or records.\nNo specific authentication or advanced privilege requirements are detailed in the exploitation vector, indicating that unauthenticated or low-privileged users may successfully manipulate the ID parameter to trigger the flaw.",
  "technicalDetails": "The vulnerability stems from improper access control enforcement within SourceCodester Online Examination & Learning Management System 1.0, specifically localized to the /view.php script.\nThe root cause of the authorization bypass is the application's failure to adequately validate whether the requesting session possesses the necessary administrative or ownership privileges to access the resource specified by the ID parameter.\nWhen a user issues a request to /view.php, the backend code retrieves data associated with the user-supplied ID parameter. Due to the absence of robust server-side authorization checks, the application implicitly trusts the input and serves the requested data or renders the underlying functionality regardless of the user's actual privilege level.\nThe attack flow proceeds as follows: First, an external attacker identifies the network exposure of the target instance running SourceCodester Online Examination & Learning Management System 1.0. Second, the attacker crafts an HTTP GET or POST request targeting /view.php. Third, the attacker manipulates the ID argument by injecting sequential, guessed, or otherwise arbitrary identifiers. Fourth, the vulnerable server processes the input, bypasses the intended access control boundary, and returns the restricted resource in the HTTP response body.\nNetwork exposure is fully remote, as the vulnerable endpoint is accessible via standard HTTP/HTTPS protocols over the web interface. The exploitation method relies entirely on parameter manipulation.\nPost-exploitation impact involves the unauthorized retrieval of confidential records, examination materials, or learning management data linked to the manipulated ID values, facilitating information disclosure and potential reconnaissance for further attacks against the application architecture."
}
CVE-2026-19064: Authorization Bypass in Online Examination (MEDIUM Severity, CVSS: 4.3) - Sceawere