A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
History

Tue, 02 Dec 2025 03:45:00 +0000

Type Values Removed Values Added
First Time appeared Kimz190
Kimz190 pre-school Management System
CPEs cpe:2.3:a:kimz190:pre-school_management_system:1.0:*:*:*:*:*:*:*
Vendors & Products Kimz190
Kimz190 pre-school Management System

Mon, 01 Dec 2025 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Sourcecodester
Sourcecodester pre-school Management System
Vendors & Products Sourcecodester
Sourcecodester pre-school Management System

Mon, 24 Nov 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 23 Nov 2025 18:45:00 +0000

Type Values Removed Values Added
Description A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
Title SourceCodester Pre-School Management System FilehelperController.php removefile denial of service
Weaknesses CWE-404
References
Metrics cvssV2_0

{'score': 5.5, 'vector': 'AV:N/AC:L/Au:S/C:N/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.4, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2025-11-24T21:13:10.913Z

Reserved: 2025-11-22T17:14:06.986Z

Link: CVE-2025-13564

cve-icon Vulnrichment

Updated: 2025-11-24T21:13:06.941Z

cve-icon NVD

Status : Analyzed

Published: 2025-11-23T19:15:46.713

Modified: 2025-12-02T03:30:15.730

Link: CVE-2025-13564

cve-icon Redhat

No data.