Impact
A flaw in the SourceCodester Client Database Management System 1.0 allows attackers to manipulate the superadmin_user_update.php endpoint and bypass the necessary authorization checks. This improper authorization can enable unauthorized modification of user accounts, including the assignment of superadmin privileges, thereby compromising data integrity and potentially granting the attacker elevated control over the system. The weakness corresponds to authorisation bypass and improper access control categories.
Affected Systems
The vulnerability affects the SourceCodester Client Database Management System version 1.0, as identified by the vendor's product listing.
Risk and Exploitability
The CVSS score of 6.9 indicates a medium severity level, while the EPSS value suggests a low probability of exploitation. The vulnerability is not recorded in the CISA Known Exploited Vulnerabilities catalog, implying no confirmed large-scale exploitation. The attack vector is remote, requiring the attacker to send crafted requests to the publicly accessible superadmin_user_update.php endpoint, which if unprotected can lead to privilege escalation or unauthorized data changes.
OpenCVE Enrichment