A vulnerability, which was classified as critical , has been found in SourceCodester Simple Client Management System 1.0 . The impacted element is an unknown function of the file /classes/Master.php?f=save_service . The manipulation of the argument ID leads to sql injection. This vulnerability is uniquely identified as CVE-2026-19825 . The attack is possible to be carried out remotely. Moreover, an exploit is present.