Impact
The vulnerability is a flaw in the Database Backup Handler component of Daily Expense Manager 1.0 that allows an attacker to manipulate the exp_ak.sql backup file and read its contents. The effect is the disclosure of potentially sensitive database information. The weakness is based on improper information exposure and insufficient authorization controls.
Affected Systems
Vendor code-projects offers the Daily Expense Manager product. The only publicly identified affected version is 1.0, and the issue involves the exp_ak.sql file used for database backups.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate severity. Because the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, there is no publicly known exploitation trend data, but an exploit has been published and is reportedly deployable remotely. The likely attack vector is remote, inferred from the statement that the attack can be launched remotely and the existence of an accessible SQL backup file. If exploited, the attacker can read database contents, compromising confidentiality and potentially enabling further attacks through data extraction.
OpenCVE Enrichment