Description
Prog
Management System developed by PROG MIS has a Exposure of Sensitive
Information vulnerability, allowing unauthenticated remote attackers to view
a specific page and obtain the database account and password.
Published: 2026-07-06
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability, identified as CWE‑497, permits an unauthenticated remote attacker to access a specific page in the Prog Management System and retrieve the database account and password. This disclosure of credential information can enable the attacker to authenticate directly to the underlying database, potentially accessing or altering stored data.

Affected Systems

All installations of PROG MIS Prog Management System are affected by this vulnerability, regardless of deployment configuration.

Risk and Exploitability

The flaw has a CVSS score of 9.3, classifying it as critical, and an EPSS score of less than 1%, indicating that exploitation is currently uncommon. It is not listed in CISA’s KEV catalog. Attackers can simply send an unauthenticated HTTP request to the exposed page; no prior login or special privileges are required.

Generated by OpenCVE AI on July 26, 2026 at 20:55 UTC.

Remediation

Vendor Solution

Contact the vendor for patching.


OpenCVE Recommended Actions

  • Contact the vendor to obtain and apply an official patch or update.
  • Restrict unauthenticated access to the vulnerable page by configuring the web server or firewall rules so that only authorized users can reach it.
  • Monitor web‑server logs for requests to the sensitive page and audit for any unauthorized or suspicious activity.

Generated by OpenCVE AI on July 26, 2026 at 20:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 06 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 06 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Prog Management System developed by PROG MIS has a Exposure of Sensitive Information vulnerability, allowing unauthenticated remote attackers to view a specific page and obtain the database account and password.
Title PROG MIS|Prog Management System - Exposure of Sensitive Information
Weaknesses CWE-497
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-07-06T18:47:01.794Z

Reserved: 2026-07-06T06:26:57.980Z

Link: CVE-2026-14808

cve-icon Vulnrichment

Updated: 2026-07-06T18:46:57.388Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T21:00:04Z

Weaknesses
  • CWE-497

    Exposure of Sensitive System Information to an Unauthorized Control Sphere