CVE-2025-12243

📊 5.3 MEDIUM0.0%🎯 0 exploits
📅 Published Oct 27, 2025
📋 Status: Analyzed

A vulnerability was found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the file clientdetails/welcome.php of the component GET Parameter Handler. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. The exploit has been made public and could be used.

🎯 Affected Products & Systems

1 product configurations affected

Filter by type:
📱
Vulnerable
Version: 1.0
CPE:
cpe:2.3:a:fabian:client_details_system:1.0:*:*:*:*:*:*:*
Metrics
5.3 MEDIUMCVSS v4.0[email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

🔍 Technical Details

Analysis Status
Analyzed
CVSS Details
5.3 (MEDIUM)v4.0
EPSS Details
0.0% (Minimal)5.5th percentile
Last updated: Oct 31, 2025
Exploitation probability within 30 days
Published Date
Oct 27, 2025 (6 days ago)
Last Modified
Oct 28, 2025 (5 days ago)
Security Weaknesses3
References5