CVE-2026-19903
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
Summary
A vulnerability has been found in SourceCodester Online Clothing Store 1.0. This affects an unknown part of the file /db/shopping.sql of the component SQL Database Backup. The manipulation leads to files or directories accessible. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| SourceCodester | Online Clothing Store | 1.0 | affected |
Weaknesses
- CWE-552: Files or Directories Accessible
- CWE-425: Direct Request
References
- https://vuldb.com/vuln/390096
- https://vuldb.com/vuln/390096/cti
- https://vuldb.com/cve/CVE-2026-19903
- https://vuldb.com/submit/870782
- https://medium.com/@hemantrajbhati5555/sensitive-information-disclosure-via-publicly-accessible-sql-backup-leading-to-administrative-50bac3a307aa
- https://www.sourcecodester.com/
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.