Improper Authorization in SourceCodester CET Automated Grading System
CVE-2026-76999

5.3MEDIUM

What is CVE-2026-76999?

A vulnerability identified in the SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 affects the add_grade function located in /index.php. This weakness arises from insufficient validation of the student_id argument, allowing unauthorized access to perform actions that should be restricted. An attacker can exploit this vulnerability remotely, which may lead to critical unauthorized changes or retrieval of sensitive information within the application.

Affected Version(s)

CET Automated Grading System with AI Predictive Analytics 1.0

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Yogender (VulDB User)
VulDB Vulnerability Moderation Team
.