PT-2025-20559 · Sourcecodester · Sourcecodester Client Database Management System

CVE-2025-46193

·

Published

2025-05-09

·

Updated

2025-12-27

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions SourceCodester Client Database Management System version 1.0
Description SourceCodester Client Database Management System version 1.0 is susceptible to remote code execution through arbitrary file upload in the user proposal update order.php file. The issue allows for the execution of code by uploading arbitrary files. The vulnerable file is user proposal update order.php.
Recommendations Update to a newer version that contains a fix for this vulnerability.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-46193

Affected Products

Sourcecodester Client Database Management System