Lerouxyxchire
Lerouxyxchire Client Database Management System: vulnerabilidades y CVE
Lerouxyxchire Client Database Management System tiene 19 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 6 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE19
Últimos 12 meses6
Críticas6
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-3764 | Media (5.5) | 0.57% | — | 8 mar 2026 | A vulnerability was determined in SourceCodester Client Database Management System 1.0. The impacted element is an unknown function of the file /superadmin_user_update.php. This manipulation causes improper… |
| CVE-2026-3762 | Media (5.5) | 0.70% | — | 8 mar 2026 | A vulnerability has been found in SourceCodester Client Database Management System 1.0/3.1. Impacted is an unknown function of the file /superadmin_delete_manager.php of the component Endpoint. The manipulation of the… |
| CVE-2026-3761 | Baja (2.1) | 0.46% | — | 8 mar 2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /superadmin_user_delete.php of the component Endpoint. Executing a manipulation of… |
| CVE-2026-3734 | Media (5.5) | 0.57% | — | 8 mar 2026 | A flaw has been found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /fetch_manager_details.php of the component Endpoint. This manipulation of the argument… |
| CVE-2025-14885 | Baja (2.1) | 0.35% | — | 18 dic 2025 | A flaw has been found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_leads.php of the component Leads Generation Module. Executing manipulation can lead to… |
| CVE-2025-63711 | Alta (7.1) | 0.20% | — | 10 nov 2025 | A Cross-Site Request Forgery (CSRF) vulnerability in the SourceCodester Client Database Management System 1.0 allows an attacker to cause an authenticated administrative user to perform user deletion actions without… |
| CVE-2025-5840 | Media (6.9) | 0.46% | — | 7 jun 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the… |
| CVE-2025-5299 | Media (6.9) | 0.63% | — | 28 may 2025 | A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation… |
| CVE-2025-5207 | Media (5.1) | 0.42% | — | 26 may 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. Affected by this issue is some unknown functionality of the file /superadmin_update_profile.php.… |
| CVE-2025-5002 | Media (6.9) | 0.51% | — | 20 may 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the… |
| CVE-2025-4924 | Media (6.9) | 0.48% | — | 19 may 2025 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the… |
| CVE-2025-4923 | Media (6.9) | 0.49% | — | 19 may 2025 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The… |
| CVE-2025-4909 | Media (6.9) | 0.51% | — | 19 may 2025 | A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory… |
| CVE-2025-46192 | Crítica (9.8) | 0.42% | — | 9 may 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. |
| CVE-2025-46191 | Crítica (9.8) | 1.2% | — | 9 may 2025 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence… |
| CVE-2025-46190 | Crítica (9.8) | 0.42% | — | 9 may 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. |
| CVE-2025-46193 | Crítica (9.8) | 0.76% | — | 9 may 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. |
| CVE-2025-46189 | Crítica (9.8) | 0.52% | — | 9 may 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. |
| CVE-2025-46188 | Crítica (9.8) | 0.67% | — | 9 may 2025 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.