PT-2025-20575 · Sourcecodester · Sourcecodester Client Database Management System
Published
2025-05-09
·
Updated
2025-12-27
·
CVE-2025-46188
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
SourceCodester Client Database Management System version 1.0
Description
SourceCodester Client Database Management System version 1.0 is susceptible to SQL Injection through the
superadmin phpmyadmin.php file. The issue allows for potential unauthorized database access and manipulation. The vulnerable file is superadmin phpmyadmin.php. The vulnerability exists due to insufficient input validation when processing requests to this file.Recommendations
Update SourceCodester Client Database Management System to a newer version that addresses this SQL Injection issue. As a temporary workaround, restrict access to the
superadmin phpmyadmin.php file to authorized personnel only.Exploit
Fix
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Sourcecodester Client Database Management System