Impact
In databasement versions prior to 1.8.2, the backup feature executes command-line utilities such as mariadb-dump with a database name supplied by an authenticated user. The supplied name is passed directly to the command without proper validation; an attacker can embed a result-file option to write to an arbitrary path, for example --result-file=/app/public/index.php. This indirect command injection allows the user to create or overwrite files through the web application, which can lead to executing arbitrary code within the web server context. The weakness aligns with CWE-88, shell command injection, and results in a high-severity, remote code execution vulnerability.
Affected Systems
The affected vendor is David‑Crty, product Databasement. Version 1.8.1 and earlier are vulnerable; any release before 1.8.2 can be exploited if the backup functionality is accessed by an authenticated user.
Risk and Exploitability
The CVSS score of 8.8 indicates a high impact risk. While the EPSS score is not published, the vulnerability is not currently listed in the CISA KEV catalog. Attackers need valid credentials with backup privileges; once granted, they can utilize the RCE to modify application files or execute arbitrary commands, making the threat likely and potentially costly for compromised hosts.
OpenCVE Enrichment