PT-2026-23972 · Sourcecodester · Client Database Management System

·

CVE-2026-3761

·

Published

2026-03-08

·

Updated

2026-03-08

CVSS v2.0

5.5

Medium

VectorAV:N/AC:L/Au:S/C:N/I:P/A:P
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description The software contains a flaw related to improper authorization. A manipulation of the user id argument in the /superadmin user delete.php endpoint can lead to unauthorized access. The exploit has been published.
Recommendations Apply any available updates to address the improper authorization issue in the /superadmin user delete.php endpoint. As a temporary workaround, restrict access to the /superadmin user delete.php endpoint. Avoid using the user id parameter in the /superadmin user delete.php endpoint until the issue is resolved.

Exploit

Fix

Incorrect Privilege Assignment

Improper Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-3761

Affected Products

Client Database Management System