CVE-2025-4909
A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
- EPSS probability
- 0.51%
- CWE
- CWE-548, CWE-552
- Published
- 2025-05-19
- Last modified
- 2026-03-13
Affected products
- SourceCodester Client Database Management System
Weakness type
Related vulnerabilities
- CVE-2026-19987 — SourceCodester Best Employee Management System Profile exposure of information through directory listing
- CVE-2026-50233 — Lyrion Music Server 9.2.0 Arbitrary Directory Listing
- CVE-2025-32750 — Dell PowerFlex Manager, version(s) <=4.6.2, contain(s) an Exposure of Information Through Directory...
- CVE-2026-41933 — Vvveb < 1.0.8.3 Directory Listing Information Disclosure
- CVE-2026-22860 — Rack has a Directory Traversal via Rack:Directory
- CVE-2023-38265 — Improper Access Control and Exposure of Information Through Directory Listing vulnerabilities affect IBM Cloud Pak System[, ]
- CVE-2020-36921 — RED-V Super Digital Signage System 5.1.1 Log Information Disclosure Vulnerability
- CVE-2022-50788 — SOUND4 IMPACT/FIRST/PULSE/Eco <=2.x Information Disclosure via Log Directory