CVE-2026-19825: SourceCodester Simple Client Management System Master.php save_service sql injection
A security vulnerability has been detected in SourceCodester Simple Client Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=saveservice. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-19825?
The severity of CVE-2026-19825 is rated as high with a CVSS score of 7.3.
What type of vulnerability is CVE-2026-19825?
CVE-2026-19825 is identified as an SQL Injection vulnerability.
How do I fix CVE-2026-19825?
To fix CVE-2026-19825, you should sanitize and validate user input in the affected function to prevent SQL injection.
Can CVE-2026-19825 be exploited remotely?
Yes, CVE-2026-19825 can be exploited remotely by an attacker.
Which software is affected by CVE-2026-19825?
CVE-2026-19825 affects the SourceCodester Simple Client Management System version 1.0.