Skip to content
Threat Feed
high threat exploited

Hard-Coded Credentials in SourceCodester Syllabus-Aligned Learning Management & Examination System

SourceCodester Syllabus-Aligned Learning Management & Examination System 1.0 contains a vulnerability in db.php that allows remote attackers to gain unauthorized access via hard-coded credentials.

CVE search metadata

CVE search record: CVE-2026-86276. Severity: high. CVSS: 7.3. KEV: no. Product: Syllabus-Aligned Learning Management & Examination System (1.0). Brief: Hard-Coded Credentials in SourceCodester Syllabus-Aligned Learning Management & Examination System. Brief link: https://feed.craftedsignal.io/briefs/2026-09-syllabus-aligned-lms-hardcoded-creds/

A critical vulnerability exists in version 1.0 of the SourceCodester Syllabus-Aligned Learning Management & Examination System. The issue resides within the 'db.php' file, which contains hard-coded credentials that can be exploited by remote, unauthenticated attackers to gain unauthorized access to the system. Since the credentials are embedded directly within the source code of the database configuration file, any instance of this software exposed to the internet is inherently vulnerable. Attackers with knowledge of the default codebase can gain administrative or database-level access without needing to perform traditional brute-force or credential-harvesting activities. Proof-of-concept exploit code has been published publicly, increasing the risk of active exploitation by opportunistic actors. Organizations currently running this specific version of the Learning Management System (LMS) should immediately restrict network access or audit the configuration to rotate compromised credentials.

Impact

Successful exploitation allows remote, unauthenticated attackers to gain unauthorized access to the application, potentially leading to full database compromise, sensitive data exfiltration, and administrative control over the learning environment. This vulnerability affects all deployments of version 1.0 of the Syllabus-Aligned Learning Management & Examination System.

Recommendation

Prioritize auditing all instances of the SourceCodester Syllabus-Aligned Learning Management & Examination System. Immediately rotate any credentials found within 'db.php' and ensure that the application is not exposed to the public internet. If the system cannot be immediately updated or secured, restrict network access to the application using a web application firewall or VPN.


Immediate actions

Restrict network access to affected LMS instances at the perimeter firewall

SOC 24h

Mitigations

Audit db.php for hard-coded credentials and implement secure configuration management

immediate IT Operations

CVE-2026-86276