Complaint Management System Codeastro Complaint Management System

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Codeastro Complaint Management System.

By the Year

In 2026 there have been 2 vulnerabilities in Codeastro Complaint Management System with an average score of 4.5 out of ten. Last year, in 2025 Complaint Management System had 2 security vulnerabilities published. If vulnerabilities keep coming in at the current rate, it appears that number of security vulnerabilities in Complaint Management System in 2026 could surpass last years number.

Year Vulnerabilities Average Score
2026 2 4.45
2025 2 0.00
2024 3 0.00

It may take a day or so for new Complaint Management System vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Codeastro Complaint Management System Security Vulnerabilities

CodeAstro 1.0 - XSS in /report/addreport Report Title via Report Handler
CVE-2026-13558 3.5 - Low - June 29, 2026

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks.

XSS

CodeAstro CMS v1.0 Auth Bypass in Report Endpoint via deletereport
CVE-2026-13549 5.4 - Medium - June 29, 2026

A security flaw has been discovered in CodeAstro Complaint Management System 1.0. The affected element is the function deletereport of the file application/controllers/Report.php of the component Report Endpoint. The manipulation results in authorization bypass. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

Insecure Direct Object Reference / IDOR

CodeAstro Complaint Mgmt Sys v1.0 /admin/m_delete.php ID Spoof Deletion (AC)
CVE-2024-56889 - February 06, 2025

Incorrect access control in the endpoint /admin/m_delete.php of CodeAstro Complaint Management System v1.0 allows unauthorized attackers to arbitrarily delete complaints via modification of the id parameter.

Remote Privilege Escalation in CodeAstro CMS 1.0 via delete_e.php
CVE-2024-55507 - January 03, 2025

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the delete_e.php component.

CodeAstro CMS 1.0 SQLi via id in delete.php
CVE-2024-55509 - December 20, 2024

SQL injection vulnerability in CodeAstro Complaint Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via the id parameter of the delete.php component.

CodeAstro Complaint Management System: IDOR Vulnerability in delete.php
CVE-2024-55506 - December 18, 2024

An IDOR vulnerability in CodeAstro's Complaint Management System v1.0 (version with 0 updates) enables an attacker to execute arbitrary code and obtain sensitive information via the delete.php file and modifying the id parameter.

CodeAstro Complaint Management System: Privilege Escalation via mess-view.php
CVE-2024-55505 - December 18, 2024

An issue in CodeAstro Complaint Management System v.1.0 allows a remote attacker to escalate privileges via the mess-view.php component.

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Codeastro Complaint Management System or by Codeastro? Click the Watch button to subscribe.

Codeastro
Vendor

subscribe