CodeAstro Complaint Management System
cpe:2.3:a:codeastro:complaint_management_system:*:*:*:*:*:*:*
- 1.0
A privilege escalation vulnerability has been identified in CodeAstro Complaint Management System version 1.0. The issue arises in the delete_e.php component, where a remote attacker can manipulate the id parameter to delete engineer-level accounts. This exploitation can be carried out without a valid session or any privileges, as the endpoint lacks proper authentication and authorization checks.
Exploitation of this vulnerability allows for unauthorized deletion of engineer-level accounts, leading to mass account deletion.
To reproduce this vulnerability, access the admin directory listing to locate the delete_e.php endpoint. Then, navigate to delete_e.php and modify the id parameter with the IDs of engineer-level accounts to delete them. This can be done without any session or privileges, taking advantage of the missing authentication and authorization checks. Tools like Burp Suite or OWASP ZAP can be used to automate the discovery of vulnerable id parameters.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.