CVE-2025-46191 is a critical arbitrary file upload vulnerability in SourceCodester Client Database Management System 1.0, specifically within the user_payment_update.php component. This flaw allows unauthenticated attackers to upload executable PHP files to a web-accessible directory due to insufficient file extension and MIME type validation. With a CVSS score of 9.8 (CRITICAL), successful exploitation grants unauthenticated Remote Code Execution (RCE), leading to full compromise of the affected system. While no public exploits are currently confirmed, the vulnerability is attracting significant community discussion, indicating potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:lerouxyxchire:client_database_management_system:1.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.