VendorsCodeAstrocomplaint_management_system1.0
Vulnerabilities

CodeAstro Complaint Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

5CVEs
CVE-2024-55509
SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.
Published 2024-12-20 · Analyzed
9.8EPSS 0.008
CVE-2024-55507
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.
Published 2025-01-03 · Analyzed
9.8EPSS 0.006
CVE-2024-55506
An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.
Published 2024-12-18 · Analyzed
8.8EPSS 0.007
CVE-2024-55505
An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.
Published 2024-12-18 · Analyzed
8.8EPSS 0.007
CVE-2024-56889
Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.
Published 2025-02-06 · Analyzed
7.5EPSS 0.007