CVE-2025-1587 MEDIUM

CVE-2025-1587: SourceCodester Telecom Billing Management System Add New Record main.cpp addrecords buffer overflow

Vendor Sourcecodester
Product Telecom Billing Management System
Weakness CWE-120
Published February 23, 2025
Last update April 2, 2025

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability was found in SourceCodester Telecom Billing Management System 1.0. It has been rated as critical. This issue affects the function addrecords of the file main.cpp of the component Add New Record. The manipulation of the argument name/phonenumber leads to buffer overflow. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Other parameters might be affected as well.

Key dates

02Disclosure timeline

February 23, 2025 CVE published
April 2, 2025 Record updated