CVE-2026-76999: SourceCodester CET Automated Grading System with AI Predictive Analytics index.php add_grade improper authorization
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function addgrade of the file /index.php. Performing a manipulation of the argument studentid results in improper authorization. The attack can be initiated remotely.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The vulnerability requires low-level privileges. Exploitation is remote and does not require user interaction.
What could an attacker manipulate?
An attacker can manipulate the student_id argument in the add_grade function of /index.php, leading to improper authorization. The provided data does not specify which unauthorized grade-related actions or records are accessible.
Which product version is known to be affected?
The affected version identified in the available data is SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0.