Junglewise Threat Intelligence

CVE-2026-9582: SourceCodester CET Automated Grading System CSRF in manage_subjects

CVE-2026-9582 · Severity: medium · CVSS 4.3 · Published 2026-05-26

Technologies: SourceCodester CET Automated Grading System with AI Predictive Analytics. Vendors: SourceCodester.

Executive brief

A security vulnerability has been identified in the SourceCodester CET Automated Grading System, a web application used for managing student grades and academic subjects. This flaw allows an attacker to trick an authorized user into unknowingly performing administrative actions, such as creating new subjects or modifying student grades. If exploited, this could lead to unauthorized changes in academic records and compromise the integrity of the grading system.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 due to missing anti-CSRF protections. The application fails to validate authenticated POST requests on sensitive endpoints, specifically /index.php?action=manage_subjects and /index.php?action=add_grade. A remote attacker can exploit this by tricking an authenticated user into visiting a malicious webpage that automatically submits hidden forms to the vulnerable application. Successful exploitation allows the attacker to create unauthorized subjects or manipulate student grading data. A public proof-of-concept (PoC) has been released.

Affected products

  • SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0

Timeline

  • 2026-05-26: disclosed: Initial disclosure and publication of CVE-2026-9582

References

Related threats