Description
A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Published: 2026-08-20
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker to obtain data from the SQL database backup file used by code-projects Login Registration System. The flaw resides in an unknown function of the backup handler, enabling remote retrieval of files or directories such as the backup file itself. The impact is the disclosure of potentially sensitive database contents, which may include user credentials or personal information. The weakness is mapped to CWE‑425 and CWE‑552, both of which involve improper handling of file permissions or locations that lead to data leakage.

Affected Systems

The affected product is code‑projects Login Registration System version 1.0. No other versions were listed, and the issue specifically references the login_registration_system.sql file within the remote‑accessible backup handler.

Risk and Exploitability

The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from public data. The vulnerability is not listed in the CISA KEV catalog, but the attack may be initiated remotely and a public exploit has been disclosed. Without mitigation, an attacker could read the entire backup file over the network, potentially compromising all stored user data.

Generated by OpenCVE AI on August 20, 2026 at 07:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade to the newest release of the Login Registration System once available.
  • Restrict file system permissions on /loginsystem/database/login_registration_system.sql so that only the database process can read it, removing read access for other users and services.
  • Configure the web server or application to deny external access to the backup directory, ensuring the .sql file is not reachable via HTTP or other protocols.

Generated by OpenCVE AI on August 20, 2026 at 07:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 02:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the file /loginsystem/database/login_registration_system.sql of the component SQL Database Backup Handler. This manipulation causes files or directories accessible. The attack may be initiated remotely. The exploit has been made available to the public and could be used for attacks.
Title code-projects Login Registration System SQL Database Backup login_registration_system.sql file access
First Time appeared Code-projects
Code-projects login Registration System
Weaknesses CWE-425
CWE-552
CPEs cpe:2.3:a:code-projects:login_registration_system:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects login Registration System
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Login Registration System
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-08-20T01:15:10.958Z

Reserved: 2026-08-19T19:21:51.211Z

Link: CVE-2026-76799

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-08-20T02:16:21.753

Modified: 2026-08-20T12:48:10.287

Link: CVE-2026-76799

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T08:00:03Z

Weaknesses
  • CWE-425

    Direct Request ('Forced Browsing')

  • CWE-552

    Files or Directories Accessible to External Parties