CVE-2026-103533 Details
Description
A vulnerability was found in David-Crty databasement up to 1.7.1. This impacts the function https:/github.com/David-Crty/databasement/pull/511 of the file app/Http/Requests/Api/V1/RestoreRequest.php of the component database-servers API Endpoint. The manipulation of the argument schema_name results in path traversal. The attack may be launched remotely. A high complexity level is associated with this attack. The exploitability is said to be difficult. The exploit has been made public and could be used. Upgrading to version 1.7.2 will fix this issue. You should upgrade the affected component.
A path traversal vulnerability has been identified in David-Crty Databasement versions prior to 1.7.1. The issue resides in the database-servers API endpoint, specifically within the RestoreRequest.php file. The vulnerability allows for the manipulation of the 'schema_name' parameter, leading to unauthorized file access. This flaw can be exploited remotely, although it requires a high level of complexity. The vulnerability has been publicly disclosed and could be actively exploited.
Upgrade to Databasement version 1.7.2, which addresses the vulnerability by applying proper validation to the 'schema_name' parameter in the RestoreRequest.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Oct 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/David-Crty/databasement/ | [email protected] | ProductVendor |
| https://github.com/David-Crty/databasement/pull/511 | [email protected] | Issue TrackingVendor |
| https://github.com/David-Crty/databasement/releases/tag/v1.7.2 | [email protected] | Release NotesVendor |
| https://github.com/David-Crty/databasement/security/advisories/GHSA-x225-463f-pgww | [email protected] | AdvisoryExploitRemedyVendor |
| https://vuldb.com/cve/CVE-2026-103533 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/957817 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/412345 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/412345/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| David-Crty databasement | >= 1.2.0, < 1.7.2 (semver) |
CPE
Remediation
| |
Change History
1 change record found show changes
| Date | Action | Recorded By |
|---|---|---|
| Oct 1, 2026 | New CVE Received | [email protected] |
Volerion