Impact
The vulnerability allows an attacker to obtain data from the SQL database backup file used by code-projects Login Registration System. The flaw resides in an unknown function of the backup handler, enabling remote retrieval of files or directories such as the backup file itself. The impact is the disclosure of potentially sensitive database contents, which may include user credentials or personal information. The weakness is mapped to CWE‑425 and CWE‑552, both of which involve improper handling of file permissions or locations that lead to data leakage.
Affected Systems
The affected product is code‑projects Login Registration System version 1.0. No other versions were listed, and the issue specifically references the login_registration_system.sql file within the remote‑accessible backup handler.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. The EPSS score is not available, so the likelihood of exploitation cannot be quantified from public data. The vulnerability is not listed in the CISA KEV catalog, but the attack may be initiated remotely and a public exploit has been disclosed. Without mitigation, an attacker could read the entire backup file over the network, potentially compromising all stored user data.
OpenCVE Enrichment