CVE-2026-76999: SourceCodester CET Automated Grading System with AI Predictive Analytics index.php add_grade improper authorization

Published Aug 20, 2026
·
Updated

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function addgrade of the file /index.php. Performing a manipulation of the argument studentid results in improper authorization. The attack can be initiated remotely.

Affected Software

1 affected component
Sourcecodester CET Automated Grading System with AI Predictive Analytics=1.0

Event History

Aug 20, 2026
CVE Published
via MITRE·03:45 PM
Data Sourced
via MITRE·03:45 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

What level of access does an attacker need to exploit this issue?

The vulnerability requires low-level privileges. Exploitation is remote and does not require user interaction.

2

What could an attacker manipulate?

An attacker can manipulate the student_id argument in the add_grade function of /index.php, leading to improper authorization. The provided data does not specify which unauthorized grade-related actions or records are accessible.

3

Which product version is known to be affected?

The affected version identified in the available data is SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203