CVE-2026-12529: SourceCodester CET Automated Grading System with AI Predictive Analytics Student Self-Registration Endpoint index.php access control
A security vulnerability has been detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. Affected is an unknown function of the file /index.php of the component Student Self-Registration Endpoint. The manipulation leads to improper access controls. Remote exploitation of the attack is possible.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Disable the Student Self-Registration feature (disable or remove handling of /index.php) until a vendor-supplied patch or fix is available.
SourceCodester CET Automated Grading System - Student Self-Registration Endpoint (/index.php) student_self_registration_enabled = false - Compensating control
Restrict access to /index.php (Student Self-Registration Endpoint) to trusted IP addresses or internal networks using network ACLs, firewall rules, or a WAF to prevent remote exploitation until the issue is remediated.
Event History
Frequently Asked Questions
What is the severity of CVE-2026-12529?
The severity of CVE-2026-12529 is classified as high with a score of 7.3.
How do I fix CVE-2026-12529?
To resolve CVE-2026-12529, you should implement proper access controls to the Student Self-Registration Endpoint in the application.
What impacts does CVE-2026-12529 have on my system?
CVE-2026-12529 can lead to improper access controls, potentially allowing unauthorized access to sensitive functions.
Is remote exploitation possible with CVE-2026-12529?
Yes, CVE-2026-12529 allows for remote exploitation due to its access control vulnerabilities.
What version of SourceCodester is affected by CVE-2026-12529?
CVE-2026-12529 affects SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0.