Unrestricted File Upload Vulnerability in SourceCodester Client Database Management System
CVE-2025-5299
Key Information:
- Vendor
Sourcecodester
- Vendor
- CVE Published:
- 28 May 2025
Badges
What is CVE-2025-5299?
The SourceCodester Client Database Management System 1.0 is susceptible to a vulnerability that allows attackers to upload files without any restrictions. This issue is due to improper handling of the 'uploaded_file_cancelled' argument in the '/user_order_customer_update.php' file. Malicious actors can exploit this security flaw remotely, leading to potential unauthorized access to the system. The vulnerability details have been publicly disclosed, raising concerns regarding the safety of suitable implementations of the affected product.
Affected Version(s)
Client Database Management System 1.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved