PT-2025-20559 · Sourcecodester · Sourcecodester Client Database Management System

Published

2025-05-09

·

Updated

2025-12-27

·

CVE-2025-46193

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description SourceCodester Client Database Management System version 1.0 is susceptible to remote code execution through arbitrary file upload in the user proposal update order.php file. The issue allows for the execution of code by uploading arbitrary files. The vulnerable file is user proposal update order.php.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-46193

Affected Products

Sourcecodester Client Database Management System