PT-2025-7687 · Sourcecodester · Sourcecodester Elearning System
Dariusz
·
Published
2025-02-23
·
Updated
2025-02-23
·
CVE-2025-1590
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester E-Learning System version 1.0
Description
A critical issue has been found, affecting an unknown function of the file /admin/modules/lesson/index.php of the component List of Lessons Page. This issue leads to unrestricted upload and can be exploited remotely.
Recommendations
For SourceCodester E-Learning System version 1.0, consider restricting access to the /admin/modules/lesson/index.php file to prevent remote exploitation until a fix is available. Additionally, monitor upload activities closely to detect and prevent potential unauthorized uploads. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Access Control
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Sourcecodester Elearning System