A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component GET Parameter Handler. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
History

Tue, 28 Oct 2025 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Fabian
Fabian client Details System
CPEs cpe:2.3:a:fabian:client_details_system:1.0:*:*:*:*:*:*:*
Vendors & Products Fabian
Fabian client Details System

Mon, 27 Oct 2025 22:30:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects client Details System
Vendors & Products Code-projects
Code-projects client Details System

Mon, 27 Oct 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Oct 2025 07:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component GET Parameter Handler. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.
Title code-projects Client Details System GET Parameter welcome.php sql injection
Weaknesses CWE-74
CWE-89
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published: 2025-10-27T07:02:16.794Z

Updated: 2025-10-27T18:31:08.218Z

Reserved: 2025-10-26T04:59:34.782Z

Link: CVE-2025-12243

cve-icon Vulnrichment

Updated: 2025-10-27T18:31:03.758Z

cve-icon NVD

Status : Analyzed

Published: 2025-10-27T07:15:40.237

Modified: 2025-10-28T02:15:54.667

Link: CVE-2025-12243

cve-icon Redhat

No data.