Permission Bypass Vulnerability in Simple Car Rental System by Code-Projects
CVE-2025-60306

9.9CRITICAL

Key Information:

Vendor
CVE Published:
10 October 2025

What is CVE-2025-60306?

The Simple Car Rental System version 1.0 developed by Code-Projects contains a security flaw that allows low privilege users to bypass permission controls. This issue enables these users to forge high privilege sessions, granting them the ability to perform sensitive operations typically reserved for higher-privilege accounts. This vulnerability poses a significant risk to the integrity of user data and system operations, highlighting the need for immediate attention to access control mechanisms.

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.