VYPR

Complaint Management System

by Codeastro

CVEs (7)

  • CVE-2024-55507CriJan 3, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

  • CVE-2024-55509CriDec 20, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.

  • CVE-2024-55506HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

  • CVE-2024-55505HigDec 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

  • CVE-2024-56889HigFeb 6, 2025
    risk 0.49cvss 7.5epss 0.01

    Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

  • CVE-2026-13558LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.…

  • CVE-2026-13549MedJun 29, 2026
    risk 0.00cvss 5.4epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can…