Impact
A flaw exists in the Vehicle Management System 1.0 where the SQL Database Backup File Handler allows an attacker to manipulate the /vehicle_management.sql file, exposing the contents of the database backup to an external user. This vulnerability can reveal sensitive data such as user credentials, operational records, or configuration information, thereby compromising confidentiality.
Affected Systems
The affected application is code‑projects Vehicle Management System 1.0. The vulnerable component is the SQL Database Backup File Handler that serves the backup file /vehicle_management.sql. No other product or version variants are listed as impacted in the available CNA data.
Risk and Exploitability
The CVSS score of 6.9 places this issue at a moderate to high severity level. Although an EPSS score is not provided, the fact that an exploit has been published indicates a realistic exploitation risk. The vulnerability is exploitable remotely, likely by requesting the backup file directly over HTTP without any authentication or authorization checks, which aligns with the CWE-200 (Information Exposure) and CWE-284 (Improper Access Control) identifiers listed.
OpenCVE Enrichment