Improper Authorization in SourceCodester CET Automated Grading System
CVE-2026-76999
5.3MEDIUM
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-76999?
A vulnerability identified in the SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 affects the add_grade function located in /index.php. This weakness arises from insufficient validation of the student_id argument, allowing unauthorized access to perform actions that should be restricted. An attacker can exploit this vulnerability remotely, which may lead to critical unauthorized changes or retrieval of sensitive information within the application.
Affected Version(s)
CET Automated Grading System with AI Predictive Analytics 1.0
References
CVSS V4
Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Yogender (VulDB User)
VulDB Vulnerability Moderation Team
