# CVE-2026-14775

> A vulnerability was identified in SourceCodester Onlne Examination & Learning Management System 1.0. Affected is an unknown function of the file /process_lesson.php. Such manipulation of the argument user_id leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. The name of the affected product appears to have a typo in it.

- **CVSS:** 6.3 (MEDIUM)
- **EPSS:** 0.2%
- **CWE:** CWE-434, CWE-284

Canonical: https://intel.threadlinqs.com/cve/CVE-2026-14775
Full threat coverage + IOCs via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
