A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
History

Wed, 27 May 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 25 May 2026 19:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom improper authorization
First Time appeared Sourcecodester
Sourcecodester student Grades Management System
Weaknesses CWE-266
CWE-285
CPEs cpe:2.3:a:sourcecodester:student_grades_management_system:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester student Grades Management System
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2026-05-25T19:00:11.404Z

Updated: 2026-05-27T18:34:21.728Z

Reserved: 2026-05-24T09:26:21.424Z

Link: CVE-2026-9484

cve-icon Vulnrichment

Updated: 2026-05-27T18:34:15.799Z

cve-icon NVD

Status : Deferred

Published: 2026-05-25T20:16:37.670

Modified: 2026-05-26T19:37:00.120

Link: CVE-2026-9484

cve-icon Redhat

No data.