Junglewise Threat Intelligence

CVE-2025-60306: code-projects Simple Car Rental System session forgery privilege escalation

CVE-2025-60306 · Severity: critical · CVSS 9.9 · Published 2025-10-10

Vendors: Code-Projects.

Executive brief

The Simple Car Rental System, a web application used for managing vehicle rentals, contains a security flaw that allows regular users to gain administrative control. By manipulating session information, a low-privileged user can impersonate an administrator and perform restricted actions, such as deleting data or modifying system settings. This could lead to a total loss of data integrity and unauthorized access to sensitive customer or business information.

Technical details

A broken access control and improper authentication vulnerability exists in code-projects Simple Car Rental System 1.0. The application fails to properly validate session tokens or enforce server-side authorization checks, allowing a low-privileged user to hijack or forge an administrative session by replacing their own session cookies with those of an administrator (or otherwise manipulating session identifiers). An authenticated attacker can exploit this to perform sensitive operations, such as deleting user messages or other administrative tasks, that should be restricted to high-privilege accounts. The vulnerability is reachable over the network and requires only basic user-level authentication to exploit.

Affected products

  • code-projects Simple Car Rental System 1.0

Timeline

  • 2025-10-10: advisory: Initial NVD publication date
  • 2025-10-10: disclosed: Vulnerability details and PoC shared on GitHub

References