CVE-2025-46188
- EPSS 0.27%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 22.05.2025 19:03:17
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
CVE-2025-46189
- EPSS 0.27%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 22.05.2025 19:01:31
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
CVE-2025-46190
- EPSS 0.24%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 22.05.2025 18:51:35
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
CVE-2025-46191
- EPSS 0.6%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 22.05.2025 18:52:07
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks,...
CVE-2025-46192
- EPSS 0.24%
- Veröffentlicht 09.05.2025 00:00:00
- Zuletzt bearbeitet 22.05.2025 18:47:48
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.