CVE-2026-9484
published 2026-05-25CVE-2026-9484: A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function…
PriorityP343medium6.3CVSS 3.1
AVNACLPRLUINSUCLILAL
EPSS
0.27%
19.1th percentile
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| sourcecodester | student_grades_management_system | — | — |
CVSS provenance
nvdv3.16.3MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
nvdv4.02.1LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
nvdv2.06.5MEDIUMAV:N/AC:L/Au:S/C:P/I:P/A:P
cvelistv5v4.05.3MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-vrf4-h9f2-qjfw: A vulnerability was determined in SourceCodester Student Grades Management System 1
ghsa_unreviewed·2026-05-26
CVE-2026-9484 [LOW] CWE-266 GHSA-vrf4-h9f2-qjfw: A vulnerability was determined in SourceCodester Student Grades Management System 1
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVEList
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
cvelistv5·2026-05-25·CVSS 5.3
CVE-2026-9484 [MEDIUM] CWE-285 SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Timeline: 2026-05-24: Advisory disclosed; 2026-05-24: VulDB entry created; 2026-05-24: VulDB entry last update
VulDB
SourceCodester Student Grades Management System 1.0 classroom.php getClassroomStudents/removeStudentFromClassroom classroom_id improper authorization
vuldb·2026-05-24
CVE-2026-9484 [CRITICAL] SourceCodester Student Grades Management System 1.0 classroom.php getClassroomStudents/removeStudentFromClassroom classroom_id improper authorization
A vulnerability categorized as critical has been discovered in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization.
The identification of this vulnerability is CVE-2026-9484. The attack may be launched remotely. Furthermore, there is an exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-05-25
Published