Impact
A vulnerability was identified in code‑projects Barangay Resident Profiling Management System 1.0. An attacker can manipulate the ID argument in the boarders.php script of the Boarder Management Module to bypass authorization checks. This allows the attacker to access or modify restricted data without proper privilege. The weakness corresponds to CWE-285 (Improper Authorization) and CWE-639 (Authorization Bypass Through User‑Controlled Parameter). The vulnerability is exploitable remotely and a publicly available exploit is documented.
Affected Systems
The affected product is code‑projects Barangay Resident Profiling Management System version 1.0. The vulnerability resides in the boarders.php file of the Boarder Management Module and impacts any deployment of this system that exposes that endpoint.
Risk and Exploitability
The CVSS base score of 5.3 reflects moderate risk, with a medium level of impact. The exploit is publicly available, but no EPSS score is provided. Because the vulnerability is not listed in KEV and no CVE annotations suggest a high exploitation likelihood, the overall risk depends on the presence of an accessible boarders.php endpoint and insufficient authorization controls. The attack can be performed over the network by supplying an erroneous or malicious ID value, resulting in unauthorized data access.
OpenCVE Enrichment