VendorsLerouxyxchireclient_database_management_system1.0
Vulnerabilities

Lerouxyxchire Client Database Management System 1.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2025-46191
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.
Published 2025-05-09 · Analyzed
9.8EPSS 0.011
CVE-2025-46193
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.
Published 2025-05-09 · Analyzed
9.8EPSS 0.007
CVE-2026-3762
SourceCodester Client Database Management System Endpoint superadmin_delete_manager.php improper authorization
Published 2026-03-08 · Analyzed
9.8EPSS 0.007
CVE-2025-46188
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
Published 2025-05-09 · Analyzed
9.8EPSS 0.006
CVE-2025-5002
SourceCodester Client Database Management System user_proposal_update_order.php sql injection
Published 2025-05-20 · Analyzed
9.8EPSS 0.005
CVE-2025-46189
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
Published 2025-05-09 · Analyzed
9.8EPSS 0.005
CVE-2025-4924
SourceCodester Client Database Management System user_void_transaction.php sql injection
Published 2025-05-19 · Analyzed
9.8EPSS 0.005
CVE-2025-5207
SourceCodester Client Database Management System superadmin_update_profile.php sql injection
Published 2025-05-26 · Analyzed
9.8EPSS 0.004
CVE-2025-46192
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.
Published 2025-05-09 · Analyzed
9.8EPSS 0.004
CVE-2025-46190
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
Published 2025-05-09 · Analyzed
9.8EPSS 0.004
CVE-2025-14885
SourceCodester Client Database Management System Leads Generation user_leads.php unrestricted upload
Published 2025-12-18 · Analyzed
8.8EPSS 0.003
CVE-2025-5299
SourceCodester Client Database Management System user_order_customer_update.php unrestricted upload
Published 2025-05-28 · Analyzed
7.5EPSS 0.006
CVE-2026-3734
SourceCodester Client Database Management System Endpoint fetch_manager_details.php improper authorization
Published 2026-03-08 · Analyzed
7.5EPSS 0.005
CVE-2026-3764
SourceCodester Client Database Management System superadmin_user_update.php improper authorization
Published 2026-03-08 · Analyzed
7.5EPSS 0.005
CVE-2025-4909
SourceCodester Client Database Management System exposure of information through directory listing
Published 2025-05-19 · Analyzed
7.5EPSS 0.005
CVE-2025-4923
SourceCodester Client Database Management System user_delivery_update.php unrestricted upload
Published 2025-05-19 · Analyzed
7.5EPSS 0.005
CVE-2025-5840
SourceCodester Client Database Management System user_update_customer_order.php unrestricted upload
Published 2025-06-07 · Analyzed
7.5EPSS 0.005
CVE-2025-63711
A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without their consent. The application's user deletion endpoint (e.g., superadmin_user_delete.php) accepts POST requests containing a user_id parameter and does not enforce request origin or anti-CSRF tokens. Because the endpoint lacks proper authentication/authorization checks and CSRF protections, a remote attacker can craft a malicious page that triggers deletion when visited by an authenticated admin, resulting in arbitrary removal of user accounts.
Published 2025-11-10 · Analyzed
7.1EPSS 0.002
CVE-2026-3761
SourceCodester Client Database Management System Endpoint superadmin_user_delete.php improper authorization
Published 2026-03-08 · Analyzed
5.5EPSS 0.004