LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-6201 - Vulnerability Analysis

MediumCVSS: 5.4

Last Updated: April 13, 2026

CodeAstro Online Job Portal - Broken Access Control

Published: April 13, 2026Updated: April 13, 2026PoC AvailableRemote Exploitable

Overview

CodeAstro Online Job Portal 1.0 contains a broken access control vulnerability caused by improper validation of the "ID" argument in /jobs/job-delete.php, letting remote attackers delete job postings without authorization.

Severity & Score

Severity: Medium
CVSS Score: 5.4

Impact

Remote attackers can delete job postings without proper authorization, leading to data loss and unauthorized modifications.

Mitigation

Update to the latest version of CodeAstro Online Job Portal.

Details

CVE ID
CVE-2026-6201
Severity
Medium
CVSS Score
5.4
Type
broken_access_control
Status
new

CWE

  • CWE-266

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L