Impact
Affected version 1.0 of code-projects Online FIR System contains a flaw in the SQL Database Backup File Handler that allows manipulation of the /complaints.sql file. The issue causes sensitive data to be stored insecurely and can be exposed to attackers. The vulnerability is traditionally identified as a confidentiality breach (CWE-200, CWE-922). Exploit code is publicly available and can be launched from a remote host.
Affected Systems
The problem affects code-projects Online FIR System version 1.0. No other versions are listed as vulnerable.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. No EPSS score is published, but the attacker can reach the vulnerable component over the network, making the exploit practical in a remote environment. The vulnerability is not yet included in CISA’s KEV catalog, yet the public availability of the exploit suggests a non‑negligible threat level for unmanaged instances of the affected system.
OpenCVE Enrichment