Description
A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used.
Published: 2026-09-08
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

The vulnerability in the Student Crud Operation 1.0 application exposes the Database file card_activation.sql through its Backup File Handler component, allowing attackers to read the contents remotely. The flaw is a classic information disclosure scenario, implicated by CWE‑200 and exacerbated by improper access control signified by CWE‑284. As a result, an attacker can obtain potentially sensitive data stored in the sql file, compromising confidentiality.

Affected Systems

The affected product is code‑projects Student Crud Operation version 1.0, running on the web application stack provided by code‑projects. Devices or servers that host this application and expose the /card_activation.sql file are vulnerable. No additional versions or sub‑products are listed in the CNA data.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating a moderate impact and moderate difficulty in exploitation. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog. The attack vector is remote, as the exploit can be launched over the network. Attackers can remotely request the exposed sql file, read its contents, and gain access to confidential information.

Generated by OpenCVE AI on September 8, 2026 at 05:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s latest patch that removes or protects the exposed card_activation.sql file in the backup handler.
  • Restrict web access to the /card_activation.sql path using server configuration or an .htaccess rule so that only authorized users can read the file.
  • Remove the card_activation.sql file from the publicly accessible directory or place it outside the web root to eliminate exposure.
  • Set file permissions to deny read access for web users, such as 600, to prevent unintended disclosure.

Generated by OpenCVE AI on September 8, 2026 at 05:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information disclosure. The attack can be launched remotely. The exploit has been made public and could be used.
Title code-projects Student Crud Operation Backup File card_activation.sql information disclosure
First Time appeared Code-projects
Code-projects student Crud Operation
Weaknesses CWE-200
CWE-284
CPEs cpe:2.3:a:code-projects:student_crud_operation:*:*:*:*:*:*:*:*
Vendors & Products Code-projects
Code-projects student Crud Operation
References
Metrics cvssV2_0

{'score': 5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:N/A:N/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 5.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Code-projects Student Crud Operation
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-11T20:34:32.486Z

Reserved: 2026-09-07T19:29:04.428Z

Link: CVE-2026-86519

cve-icon Vulnrichment

Updated: 2026-09-11T20:02:50.330Z

cve-icon NVD

Status : Deferred

Published: 2026-09-08T05:16:48.340

Modified: 2026-09-11T21:17:47.207

Link: CVE-2026-86519

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-08T05:30:09Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-284

    Improper Access Control