SQL Injection Vulnerability in SourceCodester Client Database Management System
CVE-2025-46189

9.8CRITICAL

Key Information:

Vendor
CVE Published:
9 May 2025

Badges

đź“° News Worthy

What is CVE-2025-46189?

The SourceCodester Client Database Management System version 1.0 contains a vulnerability that allows attackers to exploit SQL Injection weaknesses through the order_id parameter in the user_order_customer_update.php file. By manipulating this parameter, malicious users could potentially execute arbitrary SQL commands, leading to unauthorized access to data, data leakage, or corruption of the database. It is crucial for users of this system to implement appropriate security measures to mitigate the risk associated with this vulnerability.

News Articles

CVE-2025-46189 - Overview, Insights & Trends

Get the latest on CVE-2025-46189, including risk score and recommendations. Vulnerability intelligence on trending CVEs from multiple sources.

2 days ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • đź“°

    First article discovered by cvemon.intruder.io

  • Vulnerability published

  • Vulnerability Reserved

.