CVE-2026-6201 - Vulnerability Analysis
MediumCVSS: 5.4Last Updated: April 13, 2026
CodeAstro Online Job Portal - Broken Access Control
Published: April 13, 2026Updated: April 13, 2026PoC AvailableRemote Exploitable
Overview
CodeAstro Online Job Portal 1.0 contains a broken access control vulnerability caused by improper validation of the "ID" argument in /jobs/job-delete.php, letting remote attackers delete job postings without authorization.
Severity & Score
Severity: Medium
CVSS Score: 5.4
Impact
Remote attackers can delete job postings without proper authorization, leading to data loss and unauthorized modifications.
Mitigation
Update to the latest version of CodeAstro Online Job Portal.
References
Related Resources
Details
- CVE ID
- CVE-2026-6201
- Severity
- Medium
- CVSS Score
- 5.4
- Type
- broken_access_control
- Status
- new
CWE
- CWE-266
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L