SQL Injection Vulnerability in SourceCodester Client Database Management System
CVE-2025-46192
9.8CRITICAL
What is CVE-2025-46192?
The SourceCodester Client Database Management System version 1.0 has a vulnerability that allows SQL Injection through the user_payment_update.php script. This occurs when the 'order_id' POST parameter is manipulated, potentially enabling attackers to execute arbitrary SQL commands. Exploiting this vulnerability could compromise the integrity of the database, leading to unauthorized data access and manipulation.