Impact
The vulnerability in the Student Crud Operation 1.0 application exposes the Database file card_activation.sql through its Backup File Handler component, allowing attackers to read the contents remotely. The flaw is a classic information disclosure scenario, implicated by CWE‑200 and exacerbated by improper access control signified by CWE‑284. As a result, an attacker can obtain potentially sensitive data stored in the sql file, compromising confidentiality.
Affected Systems
The affected product is code‑projects Student Crud Operation version 1.0, running on the web application stack provided by code‑projects. Devices or servers that host this application and expose the /card_activation.sql file are vulnerable. No additional versions or sub‑products are listed in the CNA data.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate impact and moderate difficulty in exploitation. EPSS data is not available, and the issue is not currently listed in the CISA KEV catalog. The attack vector is remote, as the exploit can be launched over the network. Attackers can remotely request the exposed sql file, read its contents, and gain access to confidential information.
OpenCVE Enrichment