CVE-2025-4909 Details
Description
A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
A critical directory traversal vulnerability has been identified in SourceCodester Client Database Management System version 1.0. This vulnerability allows remote attackers to access restricted directories and files, potentially leading to unauthorized database access, sensitive data leakage, data manipulation, and in severe cases, complete system control or service disruption.
To address this vulnerability, it is recommended to implement whitelisting for allowed file paths, normalize and validate file paths to ensure they remain within intended directories, and avoid using user input directly in file paths.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/dengxun628/cve/issues/3 | CISA-ADP | ExploitIssue TrackingThird Party Advisory |
| https://github.com/dengxun628/cve/issues/3 | [email protected] | ExploitIssue TrackingThird Party Advisory |
| https://vuldb.com/?ctiid.309466 | [email protected] | Permissions RequiredVDB Entry |
| https://vuldb.com/?id.309466 | [email protected] | Third Party AdvisoryVDB Entry |
| https://vuldb.com/?submit.578723 | [email protected] | Third Party AdvisoryVDB Entry |
| https://www.sourcecodester.com/ | [email protected] | Product |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
| CWE-548 | Exposure of Information Through Directory Listing | [email protected] |
| CWE-552 | Files or Directories Accessible to External Parties | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| lerouxyxchire client database management system | 1.0 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 28, 2025 | Initial Analysis | [email protected] |
| May 19, 2025 | CVE Modified | CISA-ADP |
| May 19, 2025 | New CVE Received | [email protected] |