What is CVE-2026-19825?
A SQL injection vulnerability has been identified in SourceCodester Simple Client Management System 1.0, within an unknown function of the file /classes/Master.php?f=save_service, by manipulating the ID argument. This allows remote attackers to execute unauthorized database queries. Users are advised to update immediately or await a patch from the vendor.
Azərbaycanca: SourceCodester Simple Client Management System 1.0 proqramında /classes/Master.php?f=save_service faylındakı ID parametrinin manipulyasiyası nəticəsində SQL injection zəifliyi aşkarlanıb. Bu, uzaqdan hücumçuya verilənlər bazasına icazəsiz sorğular göndərməyə imkan verir. İstifadəçilərə dərhal proqramı yeniləmək və ya istehsalçıdan yamaq təminatı gözləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-89; shared vendor: SourceCodester
FAQ2
In which software was CVE-2026-19825 discovered?
This vulnerability was discovered in SourceCodester Simple Client Management System 1.0.
How can users protect themselves from CVE-2026-19825?
Users are advised to update immediately or await a patch from the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.