Sceawere

Vulnerability Detail

CVE-2026-76999UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CET Automated Grading Improper Authorization

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.3
Creation Date
2h ago
Vendor
SourceCodester
Product
CET Automated Grading System with AI Predictive Analytics
Attack Type
Improper Authorization
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.3",
  "pubDate": "2026-08-20T16:18:31.410Z",
  "pubdate": "2026-08-20T16:18:31.410Z",
  "executiveSummary": "An improper authorization vulnerability has been identified in the SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This security flaw specifically resides within the add_grade function located in /index.php.\nThe vulnerability allows remote attackers to bypass access controls by manipulating the student_id argument during grading operations. Successful exploitation of this flaw can result in unauthorized modification or addition of grade records within the affected system, compromising data integrity and academic records.\nThe attack vector is fully remote, requiring network connectivity to the vulnerable web application. Due to the lack of proper authorization checks, malicious actors without adequate privileges can interact with sensitive backend logic.\nOrganizations deploying this software face severe risks regarding data trustworthiness, as unauthorized entities can manipulate critical grading data. Immediate remediation is required to enforce strict session validation and authorization checks on the affected endpoint.",
  "technicalDetails": "The vulnerability stems from an insufficient authorization enforcement mechanism within the add_grade function implemented in /index.php of the SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0.\nRoot Cause: The application fails to adequately validate whether the authenticated or unauthenticated user initiating the request possesses the necessary administrative or instructor privileges to modify or submit grades for a specific student identifier.\nVulnerable Component: The backend processing logic handling the add_grade function inside /index.php.\nAttack Vector and Flow: An attacker initiates a remote HTTP request targeting /index.php where the add_grade functionality is invoked. By intercepting and manipulating the student_id parameter within the request payload, the attacker can supply arbitrary identifiers corresponding to other students in the database.\nBecause the application implicitly trusts the incoming student_id parameter without verifying session context or role-based access permissions against the target record, the system processes the request and executes unauthorized grading operations.\nNetwork Exposure and Requirements: The vulnerability is exploitable remotely over the network via standard HTTP/HTTPS protocols interacting with the web application interface. Authentication and privilege requirements depend on the baseline application state, but the core flaw allows privilege escalation or horizontal authorization bypass depending on parameter manipulation.\nImpact and Post-Exploitation: Successful exploitation leads to improper authorization, allowing malicious actors to inject, overwrite, or manipulate grade data associated with arbitrary students. This directly undermines the integrity, confidentiality, and availability of the grading infrastructure."
}
CVE-2026-76999: CET Automated Grading Improper Authorization (MEDIUM Severity, CVSS: 6.3) - Sceawere