CVE-2025-46191

CRITICAL

Client Database Management System 1.0 - Unauthenticated RCE via user_payment_update.php

Title source: llm
STIX 2.1

Description

Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload executable PHP files to a web-accessible directory (/files/). This allows them to execute arbitrary commands remotely by accessing the uploaded script, resulting in full Remote Code Execution (RCE) without authentication.

Scores

CVSS v3 9.8
EPSS 0.0098
EPSS Percentile 57.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-94
Status published
Products (1)
lerouxyxchire/client_database_management_system 1.0
Published May 09, 2025
Tracked Since Feb 18, 2026