HomeOretnom23CVE-2025-70141

CVE-2025-70141

CRITICAL
9.4CVSS
Published: 2026-02-18
Updated: 2026-02-23
AI Analysis

Description

SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
none
Scope
unchanged
Confidentiality
low
Integrity
high
Availability
high
Weaknesses
CWE-306CWE-862

Metadata

Primary Vendor
ORETNOM23
Published
2/18/2026
Last Modified
2/23/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

oretnom23 : customer_support_system

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief