Vulnerability Description
A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulation of the argument filepath results in denial of service. The attack is possible to be carried out remotely. The exploit has been released to the public and may be exploited.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Kimz190 | Pre-School Management System | 1.0 |
Related Weaknesses (CWE)
References
- https://github.com/0xffaaa/cve/blob/main/Pre_School_Management_System_Arbitrary_ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.333328Permissions RequiredVDB Entry
- https://vuldb.com/?id.333328Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.697083Third Party AdvisoryVDB Entry
- https://www.sourcecodester.com/Product
FAQ
What is CVE-2025-13564?
CVE-2025-13564 is a vulnerability with a CVSS score of 5.4 (MEDIUM). A security flaw has been discovered in SourceCodester Pre-School Management System 1.0. Impacted is the function removefile of the file app/controllers/FilehelperController.php. Performing manipulatio...
How severe is CVE-2025-13564?
CVE-2025-13564 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-13564?
Check the references section above for vendor advisories and patch information. Affected products include: Kimz190 Pre-School Management System.