SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.
History

Mon, 23 Feb 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Oretnom23
Oretnom23 customer Support System
CPEs cpe:2.3:a:oretnom23:customer_support_system:1.0:*:*:*:*:*:*:*
Vendors & Products Oretnom23
Oretnom23 customer Support System

Thu, 19 Feb 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester customer Support System
Vendors & Products Sourcecodester
Sourcecodester customer Support System

Wed, 18 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-306
CWE-862
Metrics cvssV3_1

{'score': 9.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 18 Feb 2026 17:00:00 +0000

Type Values Removed Values Added
Description SourceCodester Customer Support System 1.0 contains an incorrect access control vulnerability in ajax.php. The AJAX dispatcher does not enforce authentication or authorization before invoking administrative methods in admin_class.php based on the action parameter. An unauthenticated remote attacker can perform sensitive operations such as creating customers and deleting users (including the admin account), as well as modifying or deleting other application records (tickets, departments, comments), resulting in unauthorized data modification.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2026-02-18T00:00:00.000Z

Updated: 2026-02-18T18:31:26.903Z

Reserved: 2026-01-09T00:00:00.000Z

Link: CVE-2025-70141

cve-icon Vulnrichment

Updated: 2026-02-18T18:29:52.362Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-18T17:21:35.700

Modified: 2026-02-23T15:44:06.497

Link: CVE-2025-70141

cve-icon Redhat

No data.