📦 Client Database Management System

by Lerouxyxchire

🔍 What is Client Database Management System?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-46190

CRITICAL CVSS 9.8 May 9, 2025

This SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to execute arbitrary SQL commands through the order_id parameter in user_delivery_update.php. ...

CVE-2025-46192

CRITICAL CVSS 9.8 May 9, 2025

This vulnerability allows attackers to execute arbitrary SQL commands through the order_id parameter in user_payment_update.php. It affects SourceCodester Client Database Management System 1.0 install...

CVE-2025-46189

CRITICAL CVSS 9.8 May 9, 2025

This vulnerability allows attackers to execute arbitrary SQL commands through the order_id parameter in the user_order_customer_update.php file of SourceCodester Client Database Management System 1.0....

CVE-2025-5002

HIGH CVSS 7.3 May 20, 2025

This critical SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the order_id parameter in /user_proposal...

CVE-2025-4924

HIGH CVSS 7.3 May 19, 2025

A critical SQL injection vulnerability exists in SourceCodester Client Database Management System 1.0 through the /user_void_transaction.php file's order_id parameter. This allows remote attackers to ...

CVE-2025-4923

HIGH CVSS 7.3 May 19, 2025

This critical vulnerability in SourceCodester Client Database Management System 1.0 allows remote attackers to upload arbitrary files via the /user_delivery_update.php endpoint. The unrestricted file ...

CVE-2025-14885

MEDIUM CVSS 6.3 Dec 18, 2025

This vulnerability allows remote attackers to upload arbitrary files to SourceCodester Client Database Management System 1.0 via the /user_leads.php endpoint in the Leads Generation Module. Successful...

CVE-2025-5207

MEDIUM CVSS 4.7 May 26, 2025

This critical SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to execute arbitrary SQL commands via the nickname or email parameters in the /supera...