在 SourceCodester CET 自动评分系统(带 AI 预测分析)1.0 版本中发现了一个漏洞。该漏洞影响文件 /index.php 中的 add_grade 函数。对 student_id 参数进行操作会导致权限控制不当。该攻击可由远程发起。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | CET Automated Grading System with AI Predictive Analytics | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| SourceCodester | CET Automated Grading System with AI Predictive Analytics | 1.0 |
cpe:2.3:a:sourcecodester:cet_automated_grading_system_with_ai_predictive_analytics:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-76998 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System ajax.php delete_category sql injection |
| CVE-2026-76996 | 7.3 HIGH | SourceCodester Simple Online Food Ordering System view_order.php sql injection |
| CVE-2026-76997 | 6.3 MEDIUM | SourceCodester Simple Online Food Ordering System ajax.php save_category sql injection |
| CVE-2026-76995 | 4.7 MEDIUM | SourceCodester Simple Online Food Ordering System ajax.php save_menu unrestricted upload |
No comments yet