Tutorials-website | Employee Management System(EMS Version-1.0) | IDOR | Admin or Account Takeover via /admin/update-user.php
Hi All, I am Maloy Roy Orko CVE Number : CVE-2025-3537 Recently in one of my pentest research, I found a Employee Management System application By tutorials-website which is an open source Employee Management System Software to manage users of a company or organization. Curious to explore its functionalities, I downloaded and set it up in my local system. After fiddling with the source code, I found that the /admin/update-user.php file is vulnerable to IDOR ! It can lead into: - Unauthorized Data Access - Data Manipulation - Account Takeover - Privilege Escalation - Denial of Service (DoS) - Reputation Damage - Regulatory Consequences The Main Thing Is,If any NON-IT personal uses this template,he will fall into this vulnerability and his companies reputation can be lost too. Thats why, I am trying to inform everyone about this.