Impact
A flaw in the Movie Ticketing System allows a remote attacker to read the/db/moviedb.sql file, which contains a full backup of the database. The vulnerability is caused by an unknown function in the SQL Database Backup File Handler that incorrectly exposes the contents, thereby exposing all tables, user credentials, and personal data. This defect falls under the CWE-200 information‑disclosure category and also involves improper access control as indicated by CWE-284.
Affected Systems
The only affected product is code‑projects Movie Ticketing System version 1.0. The backup file is installed in the web‑root directory, making it reachable by external HTTP requests. No other releases or components have been reported to contain this flaw, so newer versions or differently configured deployments are presumed safe unless they retain the same backup logic.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. The vulnerability is publicly disclosed and can be exploited remotely via an HTTP request to the backup file. Because the EPSS score is unavailable and the flaw is not listed in CISA’s KEV catalog, the exact likelihood of exploitation is uncertain, but the presence of sensitive data and the remote nature of the attack warrant immediate attention. Administrators should verify whether their deployment still serves the backup file and take mitigation steps accordingly.
OpenCVE Enrichment