{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-13549","assignerOrgId":"1af790b2-7ee1-4545-860a-a788eba489b5","state":"PUBLISHED","assignerShortName":"VulDB","dateReserved":"2026-06-28T11:02:47.093Z","datePublished":"2026-06-29T08:00:09.515Z","dateUpdated":"2026-06-29T10:33:43.126Z"},"containers":{"cna":{"providerMetadata":{"orgId":"1af790b2-7ee1-4545-860a-a788eba489b5","shortName":"VulDB","dateUpdated":"2026-06-29T08:00:09.515Z"},"title":"CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization","problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-639","lang":"en","description":"Authorization Bypass"}]},{"descriptions":[{"type":"CWE","cweId":"CWE-285","lang":"en","description":"Improper Authorization"}]}],"affected":[{"vendor":"CodeAstro","product":"Complaint Management System","versions":[{"version":"1.0","status":"affected"}],"cpes":["cpe:2.3:a:codeastro:complaint_management_system:*:*:*:*:*:*:*:*"],"modules":["Report Endpoint"]}],"descriptions":[{"lang":"en","value":"A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks."}],"metrics":[{"cvssV4_0":{"version":"4.0","baseScore":5.3,"vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P","baseSeverity":"MEDIUM"}},{"cvssV3_1":{"version":"3.1","baseScore":5.4,"vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV3_0":{"version":"3.0","baseScore":5.4,"vectorString":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R","baseSeverity":"MEDIUM"}},{"cvssV2_0":{"version":"2.0","baseScore":6.4,"vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:P/E:POC/RL:ND/RC:UR"}}],"timeline":[{"time":"2026-06-28T00:00:00.000Z","lang":"en","value":"Advisory disclosed"},{"time":"2026-06-28T02:00:00.000Z","lang":"en","value":"VulDB entry created"},{"time":"2026-06-28T13:07:50.000Z","lang":"en","value":"VulDB entry last update"}],"credits":[{"lang":"en","value":"ashikmd7 (VulDB User)","type":"reporter"}],"references":[{"url":"https://vuldb.com/vuln/374557","name":"VDB-374557 | CodeAstro Complaint Management System Report Endpoint Report.php deletereport authorization","tags":["vdb-entry","technical-description"]},{"url":"https://vuldb.com/vuln/374557/cti","name":"VDB-374557 | CTI Indicators (IOB, IOC, IOA)","tags":["signature","permissions-required"]},{"url":"https://vuldb.com/cve/CVE-2026-13549","name":"CVE-2026-13549 | CVE Analysis and Report","tags":["third-party-advisory"]},{"url":"https://vuldb.com/submit/843260","name":"Submit #843260 | CodeAstro Complaint Management System v1.0 Insecure Direct Object Reference (IDOR)","tags":["third-party-advisory"]},{"url":"https://github.com/ashikmd0507/CVE/tree/main/Unauthenticated%20Arbitrary%20Report%20%26%20File%20Deletion","tags":["exploit"]},{"url":"https://codeastro.com/","tags":["product"]}]},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-06-29T10:33:25.230414Z","id":"CVE-2026-13549","options":[{"Exploitation":"poc"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-06-29T10:33:43.126Z"}}]}}