Description
A vulnerability was identified in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /jobs/job-delete.php of the component Delete Job Posting Handler. Such manipulation of the argument ID leads to improper access controls. The attack can be launched remotely. The exploit is publicly available and might be used.
Problem types
Incorrect Privilege Assignment
Product status
Timeline
| 2026-04-13: | Advisory disclosed |
| 2026-04-13: | VulDB entry created |
| 2026-04-13: | VulDB entry last update |
Credits
imad alvi (VulDB User)
References
vuldb.com/vuln/357123 (VDB-357123 | CodeAstro Online Job Portal Delete Job Posting job-delete.php access control)
vuldb.com/vuln/357123/cti (VDB-357123 | CTI Indicators (IOB, IOC, TTP, IOA))
vuldb.com/submit/797515 (Submit #797515 | CodeAstro Online Job Portal Project in PHP MySQL 1.0 Improper Access Controls)
github.com/Xmyronn/CodeAstro-Online-Job-Portal-IDOR.git
codeastro.com/