Impact
A flaw in the Restore/Delete functionality of Barangay Resident Profiling Management System allows an attacker to manipulate the resident_id parameter and bypass normal authorization checks. This enables unauthorized users to retrieve or delete archived resident records, potentially exposing or altering sensitive personal data. The weakness is identified by CWE-285 (Improper Authorization) and CWE-639 (Authorization Bypass Through User‑Controlled Key).
Affected Systems
The vulnerability affects code‑projects Barangay Resident Profiling Management System version 1.0. No additional affected versions are listed in the CNA data.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting the exploit probability is not well quantified. Nevertheless, the discovery notes that the attack may be launched remotely by manipulating resident_id, implying that a remote unit could attain full authorization bypass across the application if the proper checks are omitted.
OpenCVE Enrichment