Sourcecodester · Onlne Examination & Learning Management System · CVE-2026-14778
**Name of the Vulnerable Software and Affected Versions**
SourceCodester Onlne Examination & Learning Management System version 1.0
**Description**
Improper authorization occurs in the Enrollment Management component within the `/ajax enroll.php` endpoint. A remote attacker can manipulate the `student id`, `schedule id`, and `action` variables to bypass authorization controls.
**Recommendations**
Restrict access to the `/ajax enroll.php` endpoint or avoid using the `student id`, `schedule id`, and `action` parameters until a fix is applied.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.