The Learning Management System Project maintains a focused educational platform with vulnerability exposure concentrated in its core learning management system product. The recurring issues center on application-layer input handling, specifically SQL injection and improper file-upload validation, which reflect the data-processing demands of user-facing educational software. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Learning Management System Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-25200CRITICAL Arbitrary file upload vulnerability in SourceCodester Learning Management System v 1.0 allows attackers to execute arbitrary code, via the file upload to \lms\student_avatar.php. | Jul 30, 2021 | 9.8 | 30 | NO | NO |
CVE-2021-25201HIGH SQL injection vulnerability in Learning Management System v 1.0 allows remote attackers to execute arbitrary SQL statements through the id parameter to obtain sensitive database in | Jul 23, 2021 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Learning Management System Project.
Media articles that mention a CVE ID that affects a product developed by Learning Management System Project — matched by CVE ID, not by vendor name.