{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/syllabus-aligned-learning-management--examination-system-1.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_\u0026_examination_system:1.0:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-86276"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Syllabus-Aligned Learning Management \u0026 Examination System (1.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["SourceCodester"],"content_html":"\u003cp\u003eA critical vulnerability exists in version 1.0 of the SourceCodester Syllabus-Aligned Learning Management \u0026amp; Examination System. The issue resides within the 'db.php' file, which contains hard-coded credentials that can be exploited by remote, unauthenticated attackers to gain unauthorized access to the system. Since the credentials are embedded directly within the source code of the database configuration file, any instance of this software exposed to the internet is inherently vulnerable. Attackers with knowledge of the default codebase can gain administrative or database-level access without needing to perform traditional brute-force or credential-harvesting activities. Proof-of-concept exploit code has been published publicly, increasing the risk of active exploitation by opportunistic actors. Organizations currently running this specific version of the Learning Management System (LMS) should immediately restrict network access or audit the configuration to rotate compromised credentials.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote, unauthenticated attackers to gain unauthorized access to the application, potentially leading to full database compromise, sensitive data exfiltration, and administrative control over the learning environment. This vulnerability affects all deployments of version 1.0 of the Syllabus-Aligned Learning Management \u0026amp; Examination System.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize auditing all instances of the SourceCodester Syllabus-Aligned Learning Management \u0026amp; Examination System. Immediately rotate any credentials found within 'db.php' and ensure that the application is not exposed to the public internet. If the system cannot be immediately updated or secured, restrict network access to the application using a web application firewall or VPN.\u003c/p\u003e\n","date_modified":"2026-09-07T06:51:02Z","date_published":"2026-09-07T06:51:02Z","id":"https://feed.craftedsignal.io/briefs/2026-09-syllabus-aligned-lms-hardcoded-creds/","summary":"SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System 1.0 contains a vulnerability in db.php that allows remote attackers to gain unauthorized access via hard-coded credentials.","title":"Hard-Coded Credentials in SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System","url":"https://feed.craftedsignal.io/briefs/2026-09-syllabus-aligned-lms-hardcoded-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Syllabus-Aligned Learning Management \u0026 Examination System (1.0)","version":"https://jsonfeed.org/version/1.1"}