Impact
An unknown component of the file /db/shopping.sql in SourceCodester Online Clothing Store 1.0 can be manipulated to expose files or directories to an attacker. The flaw allows remote exploitation, enabling an adversary to retrieve sensitive data that should not be publicly available. This leads to potential compromise of customer information and other confidential database content.
Affected Systems
The affected product is SourceCodester Online Clothing Store version 1.0. No other versions are listed in the CVE data, but any installation that includes the default /db/shopping.sql backup file is vulnerable. The vulnerability is specific to the SQL Database Backup component of the web application.
Risk and Exploitability
The CVSS score is 6.9, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote: an attacker can request the backup file directly via a web browser or other network tool, and the server will return the file contents because it is publicly reachable. No additional authentication or privileges are required beyond external access to the web service.
OpenCVE Enrichment