CVE-2025-46189: SQL Injection
Published May 9, 2025
·Updated
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in userordercustomerupdate.php via the orderid POST parameter.
Affected Software
2 affected components
Sourcecodester Client Database Management System
Lerouxyxchire Client Database Management System=1.0
Event History
May 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46189?
CVE-2025-46189 is considered a high severity vulnerability due to its potential for SQL Injection exploitation.
2
How do I fix CVE-2025-46189?
To fix CVE-2025-46189, validate and sanitize the user input for the order_id POST parameter to prevent SQL Injection attacks.
3
What impact does CVE-2025-46189 have on my system?
CVE-2025-46189 can allow an attacker to manipulate database queries, potentially leading to data leakage or modification.
4
Which versions of the SourceCodester Client Database Management System are affected by CVE-2025-46189?
CVE-2025-46189 affects all versions of the SourceCodester Client Database Management System prior to the security patch.
5
Is CVE-2025-46189 actively being exploited in the wild?
There is no public information indicating active exploitation of CVE-2025-46189 in the wild at this time.