CodeAstro complaint management system是CodeAstro公司开源的一个投诉管理系统。 CodeAstro Complaint Management System 1.0版本存在授权问题漏洞,该漏洞源于Report Endpoint组件中文件application/controllers/Report.php的函数deletereport存在授权绕过问题,可能导致远程攻击者绕过授权。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CodeAstro | Complaint Management System | 1.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CodeAstro | Complaint Management System | 1.0 |
cpe:2.3:a:codeastro:complaint_management_system:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-13525 | 6.3 MEDIUM | CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php e |
| CVE-2026-13535 | 6.3 MEDIUM | CodeAstro Human Resource Management System View Endpoint Employee_model.php GetFileInfo sq |
| CVE-2026-13537 | 4.3 MEDIUM | CodeAstro Human Resource Management System cross-site request forgery |
| CVE-2026-13558 | 3.5 LOW | CodeAstro Complaint Management System Report addreport cross site scripting |
No comments yet