Junglewise Threat Intelligence

CVE-2026-12176: SourceCodester CET Automated Grading System XSS in index.php

CVE-2026-12176 · Severity: medium · CVSS 4.3 · Published 2026-06-14

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 is a web application used for managing and grading student assessments. A security vulnerability in the system allows an attacker to perform cross-site scripting (XSS) by manipulating web requests. If exploited, this could allow an attacker to execute malicious scripts in the browser of a legitimate user, potentially leading to unauthorized actions or the theft of session information.

Technical details

A cross-site scripting (XSS) vulnerability exists in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The flaw is located within the index.php file, where the 'action' parameter is improperly neutralized before being rendered in the web page. A remote attacker can exploit this by crafting a malicious URL that, when visited by a victim, executes arbitrary JavaScript in the context of the victim's browser session. This is classified as a reflected XSS vulnerability (CWE-79) and also carries risks associated with code injection (CWE-94). An exploit for this vulnerability has been disclosed publicly.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-06-14: disclosed: Public disclosure of the vulnerability and exploit.
  • 2026-06-14: advisory: CVE-2026-12176 published.

References

Related threats