CVE-2026-3734: SourceCodester Client Database Management System Endpoint fetch_manager_details.php improper authorization
A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetchmanagerdetails.php of the component Endpoint. This manipulation of the argument managerid causes improper authorization. The attack can be initiated remotely. The exploit has been published and may be used.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-3734?
CVE-2026-3734 has been classified with a moderate severity level due to improper authorization allowing unauthorized access to certain endpoints.
How do I fix CVE-2026-3734?
To fix CVE-2026-3734, ensure proper access control is enforced in the fetch_manager_details.php script to prevent unauthorized data retrieval.
What software is affected by CVE-2026-3734?
CVE-2026-3734 affects SourceCodester Client Database Management System version 1.0, specifically within the fetch_manager_details.php endpoint.
What type of vulnerability is CVE-2026-3734?
CVE-2026-3734 is categorized as an improper authorization vulnerability, allowing unauthorized access to sensitive data.
What should I do if I am using SourceCodester Client Database Management System?
If you are using SourceCodester Client Database Management System, immediately review your authorization mechanisms for the fetch_manager_details.php file to mitigate the risks of CVE-2026-3734.