CVE-2025-46190: SQL Injection
Published May 9, 2025
·Updated
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in userdeliveryupdate.php via the orderid POST parameter.
Affected Software
2 affected components
Sourcecodester Client Database Management System
Lerouxyxchire Client Database Management System=1.0
Event History
May 9, 2025
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-46190?
CVE-2025-46190 has a medium severity rating due to its potential for unauthorized database access via SQL injection.
2
How do I fix CVE-2025-46190?
To fix CVE-2025-46190, sanitize and validate user input in the order_id parameter to prevent SQL injection attacks.
3
What software is affected by CVE-2025-46190?
CVE-2025-46190 affects SourceCodester Client Database Management System version 1.0.
4
What type of vulnerability is CVE-2025-46190?
CVE-2025-46190 is classified as an SQL Injection vulnerability.
5
Can CVE-2025-46190 lead to data breach?
Yes, CVE-2025-46190 can lead to a data breach if exploited, allowing attackers to manipulate database queries.