---
cve: "CVE-2026-14777"
severity: "MEDIUM"
cvss: 5.3
epss: "21%"
vendor: "SourceCodester"
kev: false
exploited: false
published: "2026-07-06 00:16:54"
tags: [cve, security, medium]
source: tsecurity.de CVE-Dossier
exported: "2026-09-18T06:34:48+02:00"
---

# CVE-2026-14777

> 5.3 MEDIUM · 🧪 PoC

## Beschreibung

A weakness has been identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected by this issue is some unknown functionality of the file /announcements.php. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The name of the affected product appears to have a typo in it.

## CVSS-Vektor

```
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |

## Referenzen

- <https://vuldb.com/vuln/376367>
- <https://vuldb.com/vuln/376367/cti>
- <https://vuldb.com/cve/CVE-2026-14777>
- <https://vuldb.com/submit/850679>
- <https://github.com/nuiifornet/A033/blob/main/OE-LMS-RCE-3-announcements.md>
- <https://www.sourcecodester.com/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-14777) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
