Description
A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The attack may be performed from remote. The exploit is now public and may be used.
Published: 2026-04-06
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Sensitive Information Disclosure
Action: Immediate Patch
AI Analysis

Impact

Affected version 1.0 of code-projects Online FIR System contains a flaw in the SQL Database Backup File Handler that allows manipulation of the /complaints.sql file. The issue causes sensitive data to be stored insecurely and can be exposed to attackers. The vulnerability is traditionally identified as a confidentiality breach (CWE-200, CWE-922). Exploit code is publicly available and can be launched from a remote host.

Affected Systems

The problem affects code-projects Online FIR System version 1.0. No other versions are listed as vulnerable.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. No EPSS score is published, but the attacker can reach the vulnerable component over the network, making the exploit practical in a remote environment. The vulnerability is not yet included in CISA’s KEV catalog, yet the public availability of the exploit suggests a non‑negligible threat level for unmanaged instances of the affected system.

Generated by OpenCVE AI on April 6, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to the latest patch of code-projects Online FIR System or apply the vendor‑provided fix for the backup file handler.
  • Restrict file system permissions on /complaints.sql so that only privileged users can read or write.
  • Remove or relocate the backup file from publicly reachable directories if it is not required.
  • Disable the automatic backup feature if the system does not require it.
  • Regularly review audit logs for unusual access patterns to backup files and apply an intrusion monitoring solution.

Generated by OpenCVE AI on April 6, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Apr 2026 18:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Apr 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects online Fir System
Vendors & Products Code-projects
Code-projects online Fir System

Mon, 06 Apr 2026 16:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was detected in code-projects Online FIR System 1.0. Affected by this issue is some unknown functionality of the file /complaints.sql of the component SQL Database Backup File Handler. The manipulation results in insecure storage of sensitive information. The attack may be performed from remote. The exploit is now public and may be used.
Title code-projects Online FIR System SQL Database Backup File complaints.sql sensitive information
Weaknesses CWE-200
CWE-922
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Online Fir System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-07T16:00:58.394Z

Reserved: 2026-04-06T08:09:05.054Z

Link: CVE-2026-5666

cve-icon Vulnrichment

Updated: 2026-04-07T15:48:09.183Z

cve-icon NVD

Status : Deferred

Published: 2026-04-06T16:16:41.950

Modified: 2026-04-27T19:04:22.650

Link: CVE-2026-5666

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-07T09:39:30Z

Weaknesses