PT-2026-79048 · Sourcecodester · Cet Automated Grading System With Ai Predictive Analytics
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0
Description
An improper authorization issue exists in the
add grade() function within the /index.php file. A remote attacker can exploit this by manipulating the student id variable to gain unauthorized access or perform unauthorized actions.Recommendations
Update SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0 to a patched version.
As a temporary workaround, restrict access to the
add grade() function in the /index.php file to minimize the risk of exploitation.Exploit
Fix
Improper Authorization
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cet Automated Grading System With Ai Predictive Analytics