Impact
A session fixation flaw in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0 allows an attacker to set or predict a victim’s session identifier before the victim logs in. This vulnerability is classified as CWE-384, a session fixation weakness. The attacker can then hijack the session once authentication succeeds, potentially gaining unauthorized access to the victim’s account or sensitive data. The vulnerability is identified as high complexity and difficult to exploit, yet the exploit code has been made publicly available. The session fixation compromises authentication integrity and may expose confidential information.
Affected Systems
This vulnerability affects SourceCodester CET Automated Grading System with AI Predictive Analytics version 1.0, as distributed on the SourceCodester platform. No other product variants are listed in the data.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. The EPSS score is < 1%, indicating a very low exploitation probability, so the likelihood of exploitation remains uncertain but possible. The vulnerability is not currently listed in the CISA KEV catalog. Because the attack can be performed remotely and results in session hijacking, systems that rely on user authentication without proper session management represent a significant risk.
OpenCVE Enrichment