PT-2026-30417 · Unknown · Campcodes Complete Online Learning Management System

Chenkh

·

Published

2026-04-05

·

Updated

2026-04-05

·

CVE-2026-5546

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Campcodes Complete Online Learning Management System version 1.0
Description A flaw exists in Campcodes Complete Online Learning Management System version 1.0 that allows for unrestricted file upload. This is due to a manipulation within the add lesson function located in the /application/models/Crud model.php file. The attack can be initiated remotely.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the add lesson function or the /application/models/Crud model.php file.

Exploit

Fix

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-5546

Affected Products

Campcodes Complete Online Learning Management System