Description
A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used.
Published: 2026-04-10
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information disclosure
Action: Patch
AI Analysis

Impact

A vulnerability exists in the Online Library Management System version 1.0 provided by code-projects. An unknown function within the /sql/library.sql file of the SQL Database Backup File Handler allows an attacker to manipulate the backup handling process, resulting in disclosure of the entire database backup. The vulnerability can be triggered remotely and has a publicly available exploit. The exposed backup file may contain sensitive user data, authentication credentials, and other confidential information. The weakness aligns with CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).

Affected Systems

The affected system is the Online Library Management System 1.0, specifically the backup file library.sql located in the /sql directory. The product is supplied by code-projects. No further sub‑versions are listed, so any installation of version 1.0 that still retains the library.sql file in a web‑accessible location is vulnerable.

Risk and Exploitability

The CVSS v3 score of 5.3 indicates moderate severity. EPSS data is unavailable and the vulnerability does not appear in the CISA KEV catalog, suggesting it is not widely exploited yet. Nevertheless, because the flaw can be triggered remotely and the exploit code has been published, the risk of an attacker reading the backup is significant. Attackers could obtain compromised data and use it for credential stuffing, phishing, or further lateral movement within the network.

Generated by OpenCVE AI on April 10, 2026 at 03:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check for an official patch or updated version of the Online Library Management System from code-projects and apply it immediately.
  • Configure the web server or application to deny HTTP access to the /sql directory and files ending with .sql.
  • Remove the library.sql backup file from the web‑accessible directory or otherwise secure it with file system permissions.
  • Implement a web application firewall rule to block requests attempting to download or access SQL files.
  • Regularly review access logs for suspicious attempts to download database backups.

Generated by OpenCVE AI on April 10, 2026 at 03:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Apr 2026 13:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Apr 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Code-projects
Code-projects online Library Management System
Vendors & Products Code-projects
Code-projects online Library Management System

Fri, 10 Apr 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in code-projects Online Library Management System 1.0. Affected is an unknown function of the file /sql/library.sql of the component SQL Database Backup File Handler. Performing a manipulation results in information disclosure. The attack may be initiated remotely. The exploit has been made public and could be used.
Title code-projects Online Library Management System SQL Database Backup File library.sql information disclosure
Weaknesses CWE-200
CWE-284
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 4.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Online Library Management System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-04-10T12:09:00.502Z

Reserved: 2026-04-09T13:03:15.327Z

Link: CVE-2026-6000

cve-icon Vulnrichment

Updated: 2026-04-10T12:08:56.202Z

cve-icon NVD

Status : Deferred

Published: 2026-04-10T03:16:04.270

Modified: 2026-04-24T18:01:58.517

Link: CVE-2026-6000

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-10T09:27:03Z

Weaknesses