PT-2025-47857 · Sourcecodester · Sourcecodester Petshop Management System

Fany

·

Published

2025-11-23

·

Updated

2025-12-02

·

CVE-2025-13564

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Pre-School Management System version 1.0
Description A security flaw exists in SourceCodester Pre-School Management System 1.0 that can lead to a denial of service. The issue is located in the removefile function within the app/controllers/FilehelperController.php file. Manipulation of the filepath argument can trigger this condition. The attack can be carried out remotely, and an exploit has been publicly released.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2025-13564

Affected Products

Sourcecodester Petshop Management System