PT-2025-20575 · Sourcecodester · Sourcecodester Client Database Management System

Published

2025-05-09

·

Updated

2025-12-27

·

CVE-2025-46188

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description SourceCodester Client Database Management System version 1.0 is susceptible to SQL Injection through the superadmin phpmyadmin.php file. The issue allows for potential unauthorized database access and manipulation. The vulnerable file is superadmin phpmyadmin.php. The vulnerability exists due to insufficient input validation when processing requests to this file.
Recommendations Update SourceCodester Client Database Management System to a newer version that addresses this SQL Injection issue. As a temporary workaround, restrict access to the superadmin phpmyadmin.php file to authorized personnel only.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46188

Affected Products

Sourcecodester Client Database Management System