Description
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Published: 2026-08-15
Score: 6.9 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unknown component of the file /db/shopping.sql in SourceCodester Online Clothing Store 1.0 can be manipulated to expose files or directories to an attacker. The flaw allows remote exploitation, enabling an adversary to retrieve sensitive data that should not be publicly available. This leads to potential compromise of customer information and other confidential database content.

Affected Systems

The affected product is SourceCodester Online Clothing Store version 1.0. No other versions are listed in the CVE data, but any installation that includes the default /db/shopping.sql backup file is vulnerable. The vulnerability is specific to the SQL Database Backup component of the web application.

Risk and Exploitability

The CVSS score is 6.9, indicating high severity. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV. The likely attack vector is remote: an attacker can request the backup file directly via a web browser or other network tool, and the server will return the file contents because it is publicly reachable. No additional authentication or privileges are required beyond external access to the web service.

Generated by OpenCVE AI on August 15, 2026 at 19:12 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Replace or update the SourceCodester Online Clothing Store installation with the latest patched version once it is released.
  • If an update is not available, relocate the /db/shopping.sql backup file outside of the web root or block direct access to .sql files via the web server configuration.
  • Configure the web server to deny read permissions for backup files and enforce proper access controls for all database dump directories.

Generated by OpenCVE AI on August 15, 2026 at 19:12 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 15 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Title SourceCodester Online Clothing Store SQL Database Backup shopping.sql file access
First Time appeared Sourcecodester
Sourcecodester online Clothing Store
Weaknesses CWE-425
CWE-552
CPEs cpe:2.3:a:sourcecodester:online_clothing_store:*:*:*:*:*:*:*:*
Vendors & Products Sourcecodester
Sourcecodester online Clothing Store
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Sourcecodester Online Clothing Store
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-15T17:45:07.886Z

Reserved: 2026-08-14T19:24:14.926Z

Link: CVE-2026-19903

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-15T18:16:25.000

Modified: 2026-08-15T18:16:25.000

Link: CVE-2026-19903

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-15T19:15:03Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-552

    Files or Directories Accessible to External Parties