VulnerabilityAnalyzed
CVE-2025-13468
A weakness has been identified in SourceCodester Alumni Management System 1.0.
LOW 2.1EPSS 0.38%
Does this matter?
Lower severity and a low EPSS score (0.38%). Track it; it rarely justifies an emergency change on its own.
Description
A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
- CVSS 4.0
- 2.1 LOWCVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.38% probability · 31th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-862, CWE-863
- Affected
- oretnom23/alumni management system
- Source
- cna@vuldb.com
References
- https://hackmd.io/@mlgzackfly/SourceCodesterExploit, Third Party Advisory
- https://vuldb.com/?ctiid.333041Permissions Required, VDB Entry
- https://vuldb.com/?id.333041Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.694826Third Party Advisory, VDB Entry
- https://www.sourcecodester.com/Product
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.