PT-2025-20577 · Sourcecodester · Sourcecodester Client Database Management System

Published

2025-05-09

·

Updated

2025-12-27

·

CVE-2025-46190

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description SourceCodester Client Database Management System version 1.0 is susceptible to a SQL Injection issue in the 'user delivery update.php' file. The issue is triggered through the order id POST parameter. Successful exploitation could allow an attacker to manipulate database queries.
Recommendations Update to a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the 'user delivery update.php' file. Sanitize the order id POST parameter before using it in database queries.

Exploit

Fix

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46190

Affected Products

Sourcecodester Client Database Management System