A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a manipulation of the argument classroom_id can lead to improper authorization. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized.
CVE-2026-9484 is an improper authorization vulnerability in SourceCodester Student Grades Management System 1.0 that allows remote attackers to manipulate the classroom_id parameter in classroom.php to bypass access controls. The vulnerability affects student management functions and has been publicly disclosed with available exploits.
تم اكتشاف ثغرة في نظام إدارة درجات الطلاب من SourceCodester الإصدار 1.0 تسمح بتجاوز آليات التفويض. يمكن للمهاجمين البعيدين التلاعب بمعامل classroom_id في ملف classroom.php للوصول غير المصرح به إلى بيانات الطلاب والفصول الدراسية.
A vulnerability in SourceCodester Student Grades Management System 1.0 allows remote attackers to bypass authorization controls by manipulating the classroom_id parameter. This affects student management operations and poses a risk to educational institutions using this system.
Update SourceCodester Student Grades Management System to the latest patched version immediately. Implement proper input validation and authorization checks for the classroom_id parameter. Apply principle of least privilege and conduct security code review of classroom.php. Monitor access logs for suspicious classroom_id manipulation attempts.
قم بتحديث نظام إدارة درجات الطلاب إلى أحدث إصدار معدل فوراً. طبق التحقق الصحيح من المدخلات والتحقق من التفويض لمعامل classroom_id. طبق مبدأ أقل امتياز وأجرِ مراجعة أمان شاملة للكود. راقب سجلات الوصول للكشف عن محاولات التلاعب المريبة.