Improper Authorization Vulnerability in SourceCodester Student Grades Management System
CVE-2026-9484
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 25 May 2026
Badges
What is CVE-2026-9484?
A vulnerability affecting the SourceCodester Student Grades Management System version 1.0 has been identified in the function responsible for managing classroom students. This issue arises from improper handling of the classroom_id argument within the classroom.php file, which could permit unauthorized access to modify student-class assignments. The vulnerability can be exploited remotely, allowing attackers to manipulate classroom data without appropriate authorization, thereby posing a significant risk to user integrity.
Affected Version(s)
Student Grades Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
