Description
A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
Problem types
Product status
Timeline
| 2025-11-22: | Advisory disclosed |
| 2025-11-22: | VulDB entry created |
| 2025-11-22: | VulDB entry last update |
Credits
fany (VulDB User)
References
vuldb.com/?id.333328 (VDB-333328 | SourceCodester Pre-School Management System FilehelperController.php removefile denial of service)
vuldb.com/?ctiid.333328 (VDB-333328 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/?submit.697083 (Submit #697083 | Pre-School Management System 1.0 delete file)
github.com/...System_Arbitrary_File_Deletion_Vulnerabilit.md
www.sourcecodester.com/