CVE-2026-1154

A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.
Configurations

No configuration.

History

19 Jan 2026, 13:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-19 13:16

Updated : 2026-01-26 15:05


NVD link : CVE-2026-1154

Mitre link : CVE-2026-1154

CVE.ORG link : CVE-2026-1154


JSON object : View

Products Affected

No product.

CWE
CWE-74

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

CWE-80

Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)