CVE-2026-9483
published 2026-05-25CVE-2026-9483: A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a…
PriorityP343medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.26%
17.6th percentile
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | student_grades_management_system | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cvelistv5v4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-mc5h-x73m-wvcj: A vulnerability was found in SourceCodester Student Grades Management System 1
ghsa_unreviewed·2026-05-26
CVE-2026-9483 [LOW] CWE-266 GHSA-mc5h-x73m-wvcj: A vulnerability was found in SourceCodester Student Grades Management System 1
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used.
CVEList
SourceCodester Student Grades Management System grades.php improper authorization
cvelistv5·2026-05-25·CVSS 5.3
CVE-2026-9483 [MEDIUM] CWE-285 SourceCodester Student Grades Management System grades.php improper authorization
SourceCodester Student Grades Management System grades.php improper authorization
A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used.
Timeline: 2026-05-24: Advisory disclosed; 2026-05-24: VulDB entry created; 2026-05-24: VulDB entry last update
VulDB
SourceCodester Student Grades Management System 1.0 grades.php student_id improper authorization
vuldb·2026-05-24
CVE-2026-9483 [CRITICAL] SourceCodester Student Grades Management System 1.0 grades.php student_id improper authorization
A vulnerability was found in SourceCodester Student Grades Management System 1.0. It has been rated as critical. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results in improper authorization.
This vulnerability was named CVE-2026-9483. The attack may be initiated remotely. In addition, an exploit is available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published