Impact
The vulnerability resides in the Dreamweaver Metadata Files component of SourceCodester's Online Clothing Store, specifically the _notes file. An attacker can use an unspecified manipulation to trigger the exposure of file and directory information, allowing remote disclosure of sensitive data such as internal file paths, directory listings, and potentially identifying components of the application. The underlying weakness corresponds to CWE-200 (Information Exposure) and CWE-538 (Exposure of Sensitive Information).
Affected Systems
The affected product is the SourceCodester Online Clothing Store. All releases that include the Dreamweaver Metadata Files component and expose the _notes file are vulnerable. No specific version information is listed. Any deployment of this application that still contains the vulnerable _notes file and has the directory publicly reachable is at risk.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. The rule-based EPSS score was not provided, and the vulnerability is not listed in CISA KEV, but its exploit is publicly disclosed and can be launched remotely, suggesting that it could be leveraged in opportunistic attacks. The lack of authentication requirements means any remote host can attempt to access the vulnerable path, increasing the potential impact. Remediation should be prioritized to reduce the likelihood of exploitation.
OpenCVE Enrichment