CVE-2025-5299: SourceCodester Client Database Management System user_order_customer_update.php unrestricted upload
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /userordercustomerupdate.php. The manipulation of the argument uploadedfilecancelled leads to unrestricted upload. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5299?
CVE-2025-5299 has been declared as a critical vulnerability.
What component is affected by CVE-2025-5299?
CVE-2025-5299 affects the /user_order_customer_update.php file in SourceCodester Client Database Management System.
How does CVE-2025-5299 impact the system?
CVE-2025-5299 allows for unrestricted file uploads through manipulation of the uploaded_file_cancelled argument.
How do I fix CVE-2025-5299?
To fix CVE-2025-5299, ensure proper validation and sanitization of user inputs in the affected file.
What software versions are affected by CVE-2025-5299?
CVE-2025-5299 specifically affects SourceCodester Client Database Management System version 1.0.