Impact
A vulnerability exists in the Online Library Management System version 1.0 provided by code-projects. An unknown function within the /sql/library.sql file of the SQL Database Backup File Handler allows an attacker to manipulate the backup handling process, resulting in disclosure of the entire database backup. The vulnerability can be triggered remotely and has a publicly available exploit. The exposed backup file may contain sensitive user data, authentication credentials, and other confidential information. The weakness aligns with CWE‑200 (Information Exposure) and CWE‑284 (Improper Access Control).
Affected Systems
The affected system is the Online Library Management System 1.0, specifically the backup file library.sql located in the /sql directory. The product is supplied by code-projects. No further sub‑versions are listed, so any installation of version 1.0 that still retains the library.sql file in a web‑accessible location is vulnerable.
Risk and Exploitability
The CVSS v3 score of 5.3 indicates moderate severity. EPSS data is unavailable and the vulnerability does not appear in the CISA KEV catalog, suggesting it is not widely exploited yet. Nevertheless, because the flaw can be triggered remotely and the exploit code has been published, the risk of an attacker reading the backup is significant. Attackers could obtain compromised data and use it for credential stuffing, phishing, or further lateral movement within the network.
OpenCVE Enrichment