PT-2026-3438 · Unknown · Sourcecodester Elearning System

0Xcaptainfahim

·

Published

2026-01-19

·

Updated

2026-01-19

·

CVE-2026-1154

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions SourceCodester E-Learning System version 1.0
Description A cross-site scripting issue exists in the Lesson Module Handler component of SourceCodester E-Learning System 1.0. The issue is related to manipulating the Title/Description argument of an unknown function within the file /admin/modules/lesson/index.php. This manipulation can lead to basic cross-site scripting, and the attack can be executed remotely. The exploit has been published.
Recommendations Apply a fix for SourceCodester E-Learning System version 1.0.

Exploit

Fix

XSS

Special Elements Injection

Weakness Enumeration

Related Identifiers

CVE-2026-1154

Affected Products

Sourcecodester Elearning System