PT-2026-53231 · Unknown · Codeastro Complaint Management System

·

CVE-2026-13549

·

Published

2026-06-29

·

Updated

2026-06-29

CVSS v2.0

6.4

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions CodeAstro Complaint Management System version 1.0
Description An authorization bypass exists in the Report Endpoint component within the deletereport() function of the application/controllers/Report.php file. This flaw allows a remote attacker to bypass authorization requirements and execute unauthorized actions.
Recommendations As a temporary workaround, restrict access to the deletereport() function in the application/controllers/Report.php file until a fix is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

IDOR

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-13549

Affected Products

Codeastro Complaint Management System