Impact
A flaw in the Database Backup File Handler of code-projects Simple Inventory System allows an attacker to retrieve the inventorymanagement.sql file, which contains a database backup. Access to this file can expose sensitive database information, such as credentials, schema, or business data, resulting in a confidentiality compromise. The weakness maps to CWE-200 (Information Exposure) and CWE-284 (Improper Access Control)."The likely attack vector is remote, via the web interface that permits the backup file to be downloaded by unauthenticated users or attackers with minimal access."
Affected Systems
Affected product is code-projects Simple Inventory System, version 1.0. No further version information is supplied in the CVE record.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, which corresponds to moderate severity. EPSS data is not available and the issue is not listed in the CISA KEV catalog. However, the exploit has been published and can be triggered remotely, suggesting that an attacker could realistically obtain the backup file if the system is not properly secured. While the precise likelihood of exploitation remains uncertain, the combination of a moderate severity score and an available public exploit warrants timely remediation.
OpenCVE Enrichment