Description
A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Published: 2026-08-07
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Dreamweaver Metadata Files component of SourceCodester's Online Clothing Store, specifically the _notes file. An attacker can use an unspecified manipulation to trigger the exposure of file and directory information, allowing remote disclosure of sensitive data such as internal file paths, directory listings, and potentially identifying components of the application. The underlying weakness corresponds to CWE-200 (Information Exposure) and CWE-538 (Exposure of Sensitive Information).

Affected Systems

The affected product is the SourceCodester Online Clothing Store. All releases that include the Dreamweaver Metadata Files component and expose the _notes file are vulnerable. No specific version information is listed. Any deployment of this application that still contains the vulnerable _notes file and has the directory publicly reachable is at risk.

Risk and Exploitability

The CVSS score of 6.9 indicates moderate severity. The rule-based EPSS score was not provided, and the vulnerability is not listed in CISA KEV, but its exploit is publicly disclosed and can be launched remotely, suggesting that it could be leveraged in opportunistic attacks. The lack of authentication requirements means any remote host can attempt to access the vulnerable path, increasing the potential impact. Remediation should be prioritized to reduce the likelihood of exploitation.

Generated by OpenCVE AI on August 7, 2026 at 19:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official vendor patch or upgrade SourceCodester Online Clothing Store to a version that removes or protects the _notes file.
  • If an immediate patch is not available, configure the web server to block all requests to the /_notes/ directory (for example, using an .htaccess deny rule or an equivalent server configuration).
  • Continuously monitor web server logs for requests to the /_notes/ path and investigate any unauthorized access attempts.

Generated by OpenCVE AI on August 7, 2026 at 19:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 07 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
Description A vulnerability was determined in SourceCodester Online Clothing Store. Affected by this issue is some unknown functionality of the file /_notes/ of the component Dreamweaver Metadata Files. Executing a manipulation can lead to file and directory information exposure. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized.
Title SourceCodester Online Clothing Store Dreamweaver Metadata Files _notes file information disclosure
First Time appeared Sourcecodester
Sourcecodester online Clothing Store
Weaknesses CWE-200
CWE-538
CPEs cpe:2.3:a:sourcecodester:online_clothing_store:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Clothing Store
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Clothing Store
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-07T18:19:45.779Z

Reserved: 2026-08-07T10:38:54.450Z

Link: CVE-2026-19229

cve-icon Vulnrichment

Updated: 2026-08-07T18:19:40.714Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-07T19:30:04Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-538

    Insertion of Sensitive Information into Externally-Accessible File or Directory