PT-2025-24347 · Unknown · Sourcecodester Client Database Management System

Fred_Su

·

Published

2025-06-07

·

Updated

2025-06-12

·

CVE-2025-5840

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description A critical vulnerability was found in the SourceCodester Client Database Management System. This issue affects an unknown part of the file /user update customer order.php. The manipulation of the uploaded file argument leads to unrestricted upload. It is possible to initiate the attack remotely.
Recommendations For SourceCodester Client Database Management System version 1.0, consider disabling the upload functionality in the /user update customer order.php file until a patch is available. Restrict access to the uploaded file argument to minimize the risk of exploitation. Avoid using the uploaded file argument in the affected API endpoint until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Access Control

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2025-5840

Affected Products

Sourcecodester Client Database Management System