SourceCodester Client Database Management System Directory Traversal Vulnerability

Vulnerability

A critical directory traversal vulnerability has been identified in SourceCodester Client Database Management System version 1.0. This vulnerability allows remote attackers to access restricted directories and files, potentially leading to unauthorized database access, sensitive data leakage, data manipulation, and in severe cases, complete system control or service disruption.

Impact

Exploitation of this vulnerability could result in unauthorized access to the database, allowing attackers to modify or delete data, access sensitive information, or disrupt services.

Reproduction

The vulnerability can be reproduced by accessing the '/cdm/database/', '/cdm/build/', or '/cdm/uploads/' directories. This can be done by sending a request that includes directory traversal payloads to access these vulnerable paths.

Remediation

To address this vulnerability, it is recommended to implement whitelisting for allowed file paths, normalize and validate file paths to ensure they remain within intended directories, and avoid using user input directly in file paths.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.6
exploitability
8.7
remediation
0.0
relevance
0.0
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.