A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used.
PUBLISHED5.2ApplicationCWE-639CWE-285x_freeware
code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization
Problem type
Affected products
code-projects
Barangay Resident Profiling Management System
1.0 - AFFECTED
References
VDB-394527 | code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization
https://vuldb.com/vuln/394527
VDB-394527 | CTI Indicators (IOB, IOC, IOA)
https://vuldb.com/vuln/394527/cti
CVE-2026-78144 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-78144
Submit #882425 | code-projects Barangay Resident Profiling Management System (BRPMS) / Barangay San Fabian 1.0 Insecure Direct Object Reference (IDOR)
https://vuldb.com/submit/882425
gist.github.com
https://gist.github.com/c4ttr4ck/3601aa0ba9e567705823b6d425e84237
code-projects.org
https://code-projects.org/
JSON source
https://cveawg.mitre.org/api/cve/CVE-2026-78144Click to expand
{
"dataType": "CVE_RECORD",
"dataVersion": "5.2",
"cveMetadata": {
"cveId": "CVE-2026-78144",
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"dateUpdated": "2026-08-23T22:30:09.529Z",
"dateReserved": "2026-08-23T06:08:36.855Z",
"datePublished": "2026-08-23T22:30:09.529Z",
"state": "PUBLISHED"
},
"containers": {
"cna": {
"providerMetadata": {
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB",
"dateUpdated": "2026-08-23T22:30:09.529Z"
},
"title": "code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization",
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in code-projects Barangay Resident Profiling Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /boarders.php of the component Boarder Management Module. Such manipulation of the argument ID leads to authorization bypass. The attack can be executed remotely. The exploit is publicly available and might be used."
}
],
"affected": [
{
"vendor": "code-projects",
"product": "Barangay Resident Profiling Management System",
"cpes": [
"cpe:2.3:a:code-projects:barangay_resident_profiling_management_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Boarder Management Module"
],
"versions": [
{
"version": "1.0",
"status": "affected"
}
]
}
],
"problemTypes": [
{
"descriptions": [
{
"lang": "en",
"description": "Authorization Bypass",
"cweId": "CWE-639",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"lang": "en",
"description": "Improper Authorization",
"cweId": "CWE-285",
"type": "CWE"
}
]
}
],
"references": [
{
"url": "https://vuldb.com/vuln/394527",
"name": "VDB-394527 | code-projects Barangay Resident Profiling Management System Boarder Management boarders.php authorization",
"tags": [
"vdb-entry",
"technical-description"
]
},
{
"url": "https://vuldb.com/vuln/394527/cti",
"name": "VDB-394527 | CTI Indicators (IOB, IOC, IOA)",
"tags": [
"signature",
"permissions-required"
]
},
{
"url": "https://vuldb.com/cve/CVE-2026-78144",
"name": "CVE-2026-78144 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://vuldb.com/submit/882425",
"name": "Submit #882425 | code-projects Barangay Resident Profiling Management System (BRPMS) / Barangay San Fabian 1.0 Insecure Direct Object Reference (IDOR)",
"tags": [
"third-party-advisory"
]
},
{
"url": "https://gist.github.com/c4ttr4ck/3601aa0ba9e567705823b6d425e84237",
"tags": [
"exploit"
]
},
{
"url": "https://code-projects.org/",
"tags": [
"product"
]
}
],
"metrics": [
{},
{
"cvssV3_1": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV3_0": {
"version": "3.0",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"baseScore": 6.3,
"baseSeverity": "MEDIUM"
}
},
{
"cvssV2_0": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"baseScore": 6.5
}
}
],
"timeline": [
{
"time": "2026-08-23T00:00:00.000Z",
"lang": "en",
"value": "Advisory disclosed"
},
{
"time": "2026-08-23T02:00:00.000Z",
"lang": "en",
"value": "VulDB entry created"
},
{
"time": "2026-08-23T08:13:51.000Z",
"lang": "en",
"value": "VulDB entry last update"
}
],
"credits": [
{
"lang": "en",
"value": "c4ttr4ck (VulDB User)",
"type": "reporter"
}
],
"tags": [
"x_freeware"
]
}
}
}