Impact
A weakness has been identified in code-projects Patient Record Management System that allows attackers to read the /db/hcpms.sql backup file. The vulnerability can lead to the exposure of confidential patient data, compromising the confidentiality of the system and potentially violating privacy regulations. The primary weakness is a configuration or permission error that permits unauthorized access to a SQL database backup file; it is not an escalation or code execution flaw but gives attackers direct read access to sensitive information.
Affected Systems
The affected product is code-projects Patient Record Management System, version 1.0, deployed under the vendor code-projects. The flaw resides in the SQL Database Backup File Handler component, which parses or serves the backup file located at /db/hcpms.sql.
Risk and Exploitability
The CVSS base score is 5.3, indicating a moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog, but a publicly available exploit demonstrates that attackers can remotely retrieve the backup file. The attack vector is remote access over the network, and the exploit requires no authentication, making this vulnerability highly accessible to external adversaries.
OpenCVE Enrichment