Medium severity5.4NVD Advisory· Published Nov 20, 2025· Updated Apr 29, 2026
CVE-2025-13468
CVE-2025-13468
Description
A weakness has been identified in SourceCodester Alumni Management System 1.0. This issue affects the function delete_forum/delete_career/delete_comment/delete_gallery/delete_event of the file admin/admin_class.php of the component Delete Handler. Executing manipulation of the argument ID can lead to missing authorization. It is possible to launch the attack remotely. The exploit has been made available to the public and could be exploited.
Affected products
1- cpe:2.3:a:oretnom23:alumni_management_system:1.0:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
5- hackmd.io/@mlgzackfly/SourceCodesternvdExploitThird Party Advisory
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdThird Party AdvisoryVDB Entry
- vuldb.comnvdPermissions RequiredVDB Entry
- www.sourcecodester.comnvdProduct
News mentions
0No linked articles in our index yet.