Impact
The vulnerability resides in an unvalidated function within the /index.php file of the SourceCodester CET Automated Grading System with AI Predictive Analytics. By manipulating the action argument, an attacker can inject arbitrary JavaScript or HTML, leading to cross‑site scripting attacks. This weakness can be exploited remotely, potentially allowing attackers to deface the application, steal session cookies, or execute malicious scripts in the context of authenticated users, thereby compromising confidentiality and integrity of user data.
Affected Systems
The affected product is SourceCodester CET Automated Grading System with AI Predictive Analytics, version 1.0. No additional sub‑versions are explicitly listed, but any instance of version 1.0 remains vulnerable.
Risk and Exploitability
The CVSS score of 5.3 indicates a medium severity for this XSS flaw. The EPSS score is not available, but the lack of an EPSS entry does not negate the risk, especially since the exploit is publicly disclosed and can be triggered by remote actors making crafted HTTP requests against /index.php. The vulnerability is not listed in CISA’s KEV catalog, yet its remote nature and potential for user data exposure warrant proactive mitigation.
OpenCVE Enrichment