Description
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.
Published: 2026-07-03
Score: 6.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A session fixation flaw in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 allows an attacker to set or predict a victim’s session identifier before the victim logs in. This vulnerability is classified as CWE-384, a session fixation weakness. The attacker can then hijack the session once authentication succeeds, potentially gaining unauthorized access to the victim’s account or sensitive data. The vulnerability is identified as high complexity and difficult to exploit, yet the exploit code has been made publicly available. The session fixation compromises authentication integrity and may expose confidential information.

Affected Systems

This vulnerability affects SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0, as distributed on the SourceCodester platform. No other product variants are listed in the data.

Risk and Exploitability

The CVSS score of 6.3 indicates moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, so the likelihood of exploitation remains uncertain but possible. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack can be performed remotely and results in session hijacking, systems that rely on user authentication without proper session management represent a significant risk.

Generated by OpenCVE AI on July 21, 2026 at 09:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the application to the latest version or apply the official vendor patch if one is available.
  • Modify the application logic so that session identifiers are regenerated immediately after a successful login to prevent fixation.
  • Configure the session cookie with the HttpOnly and Secure flags and enforce HTTPS to protect session data in transit.

Generated by OpenCVE AI on July 21, 2026 at 09:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This issue affects some unknown processing. The manipulation results in session fixiation. The attack can be executed remotely. The attack requires a high level of complexity. The exploitability is assessed as difficult. The exploit is now public and may be used.
Title SourceCodester CET Automated Grading System with AI Predictive Analytics session fixiation
First Time appeared Sourcecodester
Sourcecodester cet Automated Grading System With Ai Predictive Analytics
Weaknesses CWE-384
CPEs cpe:2.3:a:sourcecodester:cet_automated_grading_system_with_ai_predictive_analytics:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester cet Automated Grading System With Ai Predictive Analytics
References
Metrics cvssV2_0

{'score': 5.1, 'vector': 'AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.6, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.6, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.3, 'vector': 'CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Cet Automated Grading System With Ai Predictive Analytics
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-06T16:52:16.672Z

Reserved: 2026-07-03T13:58:44.213Z

Link: CVE-2026-14609

cve-icon Vulnrichment

Updated: 2026-07-06T16:05:11.112Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T09:45:04Z

Weaknesses