CVE-2026-1154

MEDIUM

Janobe E-learning System - Basic XSS

Title source: rule
STIX 2.1

Description

A flaw has been found in SourceCodester E-Learning System 1.0. This impacts an unknown function of the file /admin/modules/lesson/index.php of the component Lesson Module Handler. Executing a manipulation of the argument Title/Description can lead to basic cross site scripting. The attack can be executed remotely. The exploit has been published and may be used.

Scores

CVSS v3 4.3
EPSS 0.0004
EPSS Percentile 11.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-74 CWE-80
Status published
Products (1)
janobe/e-learning_system 1.0
Published Jan 19, 2026
Tracked Since Feb 18, 2026