PT-2026-23973 · Sourcecodester · Client Database Management System

Adarsh007

·

Publicado

2026-03-08

·

Atualizado

2026-03-13

·

CVE-2026-3762

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System versions 1.0 through 3.1
Description A flaw exists in the Endpoint component of the software, specifically within the /superadmin delete manager.php file. Improper authorization can be triggered by manipulating the manager id argument. This allows for remote exploitation. The exploit has been publicly disclosed.
Recommendations Versions prior to 1.0 and 3.1 are not affected. Versions 1.0 and 3.1: Address improper authorization by carefully validating the manager id argument in the /superadmin delete manager.php file.

Exploit

Correção

Improper Authorization

Incorrect Privilege Assignment

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-3762

Produtos afetados

Client Database Management System